All Apps and Add-ons

Pulling Exchange message tracking logs using Microsoft Office 365 Reporting Add-on for Splunk is not working anymore


Does someone knows if it is still possible to pull the Exchange message tracking logs using the Microsoft Office 365 Reporting Add-on for Splunk? I have followed the setup instructions and it worked for 8 day circa then stopped working for a month, then suddenly started working again, but just for a day. Examining the logs I've noticed messages saying "HTTP 401 Unauthorized ... call not properly authenticated", but I've never changed credentials. In another question ( I've read that " O365 no longer supports basic authentication for O365 to get those log files.", but it worked for a while so I do not understand. Did someone came up with a solution for this?



Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...