All Apps and Add-ons

Splunk Add-on for Microsoft Office 365: Will not return any DLP events but returns all others. Any ideas?

ChadLangUAB
Path Finder

I've confirmed that, as required, the Splunk API account has the correct Application and Delegated permissions to read the service health, activity data, and DLP policy events. These permissions are selected, saved and then granted within the Office 365 Management Activity API configuration on Azure Active Directory.

Also confirmed that the account has Microsoft Office 365 E3 license applied.

We are really at wit's end and have had a support case open since 7/21.

Hopefully, someone here has some experience with this issue.

esalmon
Explorer

Bumping this up because we have the same issue

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...