All Apps and Add-ons

Splunk Add-on for Microsoft Security -Threat Intelligence datasets

norbertt911
Communicator

Hello,

Is there anybody who set this input? I have the ThreatIntelligence.Read.All permission missing error during the input configuration. This permission is already added to the app on the Azure side. (MS Graph permission).

The documentation says nothing... (all other inputs are ok)

Thanks, 
Norbert

Labels (1)
0 Karma

tscroggins
Influencer

Hi @norbertt911,

Absent more information, verify admin consent has been granted for your application. See https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/grant-admin-consent for more information.

 

0 Karma

norbertt911
Communicator

Hello, 

Admin consent is already there...

But I think I figured out...

First of all it will not work with the https://graph.microsoft.com/v1.0/security.... endpionts, just with https://graph.microsoft.com/beta/security...

Second (and this is the issue in my case): it needs a Microsoft Defender Threat Intelligence license (MDTI add-on subscription) for the tenant.

0 Karma
Get Updates on the Splunk Community!

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...