Hi at all,
I installed an heavy forwarder to send all Office365 logs to Splunk and use them in Office365App.
In the beginning there was an error because in searches there isn't index indication and I solved modifying an App macro inserting the index=office365 filter and now all the panels correctly run except the one for MS-Exchange.
This is the search of this panel:
sourcetype="ms:o365:reporting:messagetrace" action=Delivered OR action=FilteredAsSpam OR action=Failed OR action=Quarantined
| timechart dc(internal_message_id) by action
At first, tried to insert index = office365 in the search with no results.
After I found that that sourcetype isn't present in my logs and that the "action" field isn't defined.
Anyone has encountered this (or similar) problem?
Anyone has a tip to search the problem?