I realise this is an old thread, but apparently still relevant! I have the same issue, (and have done in the past). Previously I asked Splunk support to fix it, and they did.... After about 2 weeks. When I go to Indexes in the IDM, I can see all the indexes (60 of them) so the index.conf file must have been copied over to the IDM from our Search Head. However, the Office 365 app can only see the default 3, plus the one I previously asked support to make visible. When I run your query, I only see a few - what does this mean? I have admin rights already, so that cant be the issue. I even tried adding my user to every role available!
... View more