All Apps and Add-ons

Splunk Add-on for Microsoft Office 365 : Returning "500 Server Error: Internal Server Error for url" and sourcetypes not reporting in.

New Member

The add on for splunk, Microsoft Office 365 has not been working on the front end and throws a 500 error and has been causing issues with sourcetypes not reporting in.

Theres nothing wrong with the account for the add on

I have checked splunkd and found these logs.

0500 INFO SpecFiles - Found external scheme definition for stanza="splunktao365servicestatus://" from spec file="/opt/splunk/etc/apps/TPA-TA-microsoftofficeO365/README/inputs.conf.spec" with parameters="tenantname, contenttype"

0500 INFO SpecFiles - Found external scheme definition for stanza="mso365messagetrace://" from spec file="/opt/splunk/etc/apps/TA-MSO365Reporting/README/inputs.conf.spec" with parameters="inputmode, office365username, office365password, querywindowsize, delaythrottle, startdatetime, enddate_time"

0500 INFO SpecFiles - Found external scheme definition for stanza="splunktao365managementactivity://" from spec file="/opt/splunk/etc/apps/TPA-TA-microsoftofficeO365/README/inputs.conf.spec" with parameters="tenantname, contenttype, numberofthreads"

0500 INFO SpecFiles - Found external scheme definition for stanza="splunktao365servicemessage://" from spec file="/opt/splunk/etc/apps/TPA-TA-microsoftofficeO365/README/inputs.conf.spec" with parameters="tenant_name"

0500 WARN CalcFieldProcessor - Invalid eval expression for 'EVAL-vendor_product' in stanza [ms:o365:reporting:messagetrace]: The expression is malformed. Expected OR.

0 Karma