Getting Data In

Expired key microsoft 365 app

splunkcol
Builder

 

I have configured the APP for microsoft 365 which was working properly but it stopped working and after checking it was found that one of the keys or certificates had expired.

I contacted the administrator asking him for the "Client Secret" and he gave me the information but he also asks for the "Cloud App Security Token" field and I really have no idea what information I should ask the administrator for.

I would be grateful if you could explain me if it is possible.

Thanks

splunkcol_0-1702484874304.png

 

0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven't check this for some time, but at least earlier that could be empty. See https://data-findings.com/wp-content/uploads/2023/04/M365-app-and-TAs-2023-03-15-sanitised.pdf page 13.

r. Ismo

View solution in original post

rajd2024
Observer

@splunkcol  the update of plugin worked - your reply helped my friend. I wish you the best.

0 Karma

rajd2024
Observer

Hi @splunkcol  what was your fix? We have exact same issue. Its a mandatory field as soon we update the secret key - and doesn't allow save. 

0 Karma

splunkcol
Builder

Hi, forgive my English, I'm using a translator.

About the problem it is better that you send a ticket to Splunk directly, it seems to be a bug in the end I gave up because whenever they ask about the version of splunk they always make the excuse that they do not support old versions of Splunk, in this case although it is true that I was using an old version of Splunk clearly the problem was the add-on.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven't check this for some time, but at least earlier that could be empty. See https://data-findings.com/wp-content/uploads/2023/04/M365-app-and-TAs-2023-03-15-sanitised.pdf page 13.

r. Ismo

splunkcol
Builder

Thank you very much for your valuable help, you are right the field below should be optional but for some reason it is a mandatory field.

I will send a ticket

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...