All Apps and Add-ons

Office365 Mgmt API User Login/Logoff messages stopped indexing

Champion

Anyone run into an issue where the User Logon/Logoff events from O365 stop indexing from the Splunk Add-on for Microsoft Office 365? Other events are still appearing, but these stopped. Our O365 admin ran a powershell script using the same credentials as the plugin, and the events appeared, so I don't think that it's an issue with the account, or Microsoft. The plugin doc provided some additional steps to assist with trouble-shooting, but those did not solve the issue either.

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!