Add on was working fine for months. Recently stopped - no changes on Splunk side (that I am aware of). I suspect a change on the MS portal, but I would expect more people would be seeing failures if that was the case so....
tail splunk_ta_o365_management_activity_nord_o365_DLP_All.log
File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunk_ta_o365/common/token.py", line 56, in auth
self.token = self._policy(self._resource, session)
File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunk_ta_o365/common/token.py", line 37, in __call_
return self.portal.get_token_by_psk(self._client_id, self._client_secret, resource, session)
File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunk_ta_o365/common/portal.py", line 89, in get_token_by_psk
raise O365PortalError(response)
File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunk_ta_o365/common/portal.py", line 23, in __init_
self._code = data['error']['code']
TypeError: string indices must be integers
Opened a case with Splunk support. Created a new client secret and events started flowing. This has happened multiple times and other customers have reported it as well. Splunk is investigating.
Did you get an answer to this?
Opened a case with Splunk support. Created a new client secret and events started flowing. This has happened multiple times and other customers have reported it as well. Splunk is investigating.
This also seems to happen if your client secret is incorrect.
This worked for me.