Hello,
We have a Splunk indexer cluster with two searchheads and would like to use the addon in the cluster: https://splunkbase.splunk.com/app/4055
We installed the addon on the searchhead without ES and on all indexers via ClusterManager App.
Then we set up all the inputs for the addon on the searchhead and could not select the index “M365” but only enter it manually.
The problem now is that this index is not filled by the indexers!
What are we doing wrong here?
Hi
i’m not sure if I understand correctly how you have installed ad configured it? Have you followed this instructions where to install it https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Install/ ? And then followed this how to configure it https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureAppinAzureAD/ ?
Following those steps it should work. If not then you should look troubleshooting from here https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Troubleshooting/
r. Ismo
First and foremost - you should not configure inputs on a search head. Set up a separate HF with those inputs and only use SHs for searching.
There might be more issues with your overall setup that we don't know about.
Hi
i’m not sure if I understand correctly how you have installed ad configured it? Have you followed this instructions where to install it https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Install/ ? And then followed this how to configure it https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureAppinAzureAD/ ?
Following those steps it should work. If not then you should look troubleshooting from here https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Troubleshooting/
r. Ismo
Thanks for the quick replies, we have configured a HF and removed the input from the SH.
With the help of the guides we also managed to set the necessary EntraID permissions for the app.
Now it works and all dashboards show data.
Thank you very much!
many thanks for the advice, we have now seperated all inputs to the HF. SH is now just for searching but has the TA installed.
@PickleRick many thanks also for the hint!