Hello, All.
I find this question without answer.
And i have this error too. And may be anyone know how to fix it?
But some logs collect in splunk.
Hello, @lfedak_splunk.
No, it's not working for me. I checked it before write question.
Today i try reconfigured this app using this post
I was skip one step - 36) Creating Azure Audit input. (I am currently only interested in data from office 365)
And if i use one inputs Office 365 Management APIs all looks good in O365 Troubleshooting
Data comes to splunk, but very slowly, in this moment (15:35 GMT+3) i have only data before 12:56 GMT+3
Hello, @lfedak_splunk.
No, it's not working for me. I checked it before write question.
Today i try reconfigured this app using this post
I was skip one step - 36) Creating Azure Audit input. (I am currently only interested in data from office 365)
And if i use one inputs Office 365 Management APIs all looks good in O365 Troubleshooting
Data comes to splunk, but very slowly, in this moment (15:35 GMT+3) i have only data before 12:56 GMT+3
All work fine. But one moment - when we test approach every minute, we have an error - the are many connecting.
And re-create input for approach every 15 minute
Hi @templier, Did @catate's solution not work from that post? ("I was having the same problem and was able to resolve it by removing spaces in the Inputs and Account names.")