All Apps and Add-ons

Why did the Splunk Add-on for Microsoft Office 365 TA fail to get data and service status stop working?

fde
Engager

Hello,

We 've got some problem with the service status part of the Splunk Add-on for Microsoft Office 365, since monday evening.

The TA failed to get data and report the following message: "splunk_ta_o365.common.portal.O365PortalError: 403:Please use MSGraph to access this resource https://docs.microsoft.com/en-us/graph/api
/resources/service-communications-api-overview?view=graph-rest-1.0&preserve-view=true" .

I've seen a link on microsoft doc "https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-service-communications-... which says that the "Office 365 Service Communications API" will be retired and is replace by MS Graph API

Do you know if an updated TA would be post soon ?

Thanks

Labels (1)

lskaariwala
Loves-to-Learn Lots

The new version(3.0.0) had this covered. 

https://splunkbase.splunk.com/app/4055/#/overview

I see latest version 4.1.0 was released 2 days back. Upgrade the O365 Add-on and you should be good. 

0 Karma

lskaariwala
Loves-to-Learn Lots

I have 2.1.0 and have similar error 

0 Karma

netman2900
Explorer

Yes this issue will impact all currently released versions as one of the Microsoft API's it uses has been decommissioned 

0 Karma

BornSleepy
Loves-to-Learn

Hi @netman2900 

Thanks for raising this ticket. Did you get a response on when support for the graph API will be added?

 

0 Karma

netman2900
Explorer

I received a response to my splunk ticket yesterday, splunk are working on an update for this add on to use the graph api but i don't have an eta for it as yet.

kman_2000
Engager

Thanks for the update @netman2900 
If you hear any further updates please post back here. That would be much appreciated.

0 Karma

netman2900
Explorer

From what I have heard today the ETA will be several weeks, I will probably hear something further late next week.

netman2900
Explorer

Got a further reply, ETA for add on update is mid Feb.

0 Karma

netman2900
Explorer

Just got word that the version to fix this issue (3.0) has just been released and is now available on splunkbase.

mccurity
Explorer

Same issue here.  I'm on version 2.1.0 but see there's an update to 2.2.0.  Is anyone having this issue on 2.2.0 also?

0 Karma

fde
Engager

Hi,

I'm having the issue on 2.2.0 version.

 

fde

0 Karma

ktanetic
Loves-to-Learn

We happen to have the issue, with a TA on our side, did you happen to find a way around it?

0 Karma

kman_2000
Engager

Anyone get it working?

v2.2.0  here and it broke at 1900 3/1/2022  GMT....

 

0 Karma

netman2900
Explorer

It has impacted me as well, I reported to splunk today given its a splunk supported add on, will update if i get response

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...