All Apps and Add-ons

Why are the management_api tokens failing to renew in Splunk Add-on for Microsoft Cloud Services?

dimarra
Explorer

It appears that the management_api access token do not renew during normal operations and requires a restart of the splunk instance to force a renewal. These tokens are short-lived (59 min 59 sec). After which no ms:o365:management sourcetype data are successfully retrieved. Waited several hours before restarting. No data was retrieved until a restart was performed which resumed the data ingestion for this sourcetype.

Has anyone observed this behavior and resolved this successfully?

Is this a known TA bug?

Thanks

jconger
Splunk Employee
Splunk Employee

Did you configure a certificate? The certificate it used in the background to refresh API tokens -> https://msdn.microsoft.com/en-us/office-365/get-started-with-office-365-management-apis#configure-an...

For details on configuring a certificate, see this blog (step 29) https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html

You can check the status of your certificate by going to O365 Troubleshooting tab in the add-on. You should see the text "Auto-generated and verified as valid" or similar depending on whether you used generated certificate or your own certificate.
,Did you configure a certificate? The certificate it used in the background to refresh API tokens -> https://msdn.microsoft.com/en-us/office-365/get-started-with-office-365-management-apis#configure-an...

For details on configuring a certificate, see this blog (step 29) https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html

You can check the status of your certificate by going to O365 Troubleshooting tab in the add-on. You should see the text "Auto-generated and verified as valid" or similar depending on whether you used generated certificate or your own certificate.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...