Getting Data In

Teams add-on for Splunk - missing call records

navotfk
Loves-to-Learn Lots

Hi Team,

We had successfully leveraged MS Teams Add-On for Splunk to collect Teams call records and user reports data until recently. This past July we switched our systems to GCCH and since then we’ve only been collecting user reports from the Add-On, no call records.

After some troubleshooting, we found this error in the Splunk internal logs ("_Splunk_ Could not get access token") but couldn’t figure out how to resolve it. All access look good on our end but still the error persists.

Please any help would be appreciated

Labels (2)
0 Karma

navotfk
Loves-to-Learn Lots

An update on this issue: 
I am now getting this error in Splunk. Any idea what could be the issue here? Firewall rules have been checked and all, no messages from graph are being dropped.

navotfk_0-1762972115333.png

 

0 Karma

thahir
Contributor

@navotfk  Can you share your endpoint which you are using in the app.

0 Karma

navotfk
Loves-to-Learn Lots

@thahir any ideas please?

0 Karma

navotfk
Loves-to-Learn Lots

@thahir  the endpoint i picked in the app: v1.0

0 Karma

navotfk
Loves-to-Learn Lots

v1.0

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @navotfk 

Can you confirm that you've entered the secret "Value" and not the "Secret ID" from the Azure Portal? Ive seen this mistake made previously and give this error.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

navotfk
Loves-to-Learn Lots

@livehybrid yes, I am using the secret value.

0 Karma

navotfk
Loves-to-Learn Lots

@thahir yes, and verified client, secret and environment are correct.  Teams add-on is installed on the HF only

I also found this document_link that I followed but still no results.

0 Karma

thahir
Contributor

@navotfk , Did you give the below API permission in the Azure portal?

CallRecords.Read.All

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...