All Apps and Add-ons

Office 365 data import app: Why am I unable to view the Malware Detail Report?

billford
Path Finder

I tried to email the app author, but it bounced (well told me I wasn't allowed to send). I'm trying to pull down the malware detail report and when I try by hand, it's empty. Anyone know if there's a different REST endpoint than the one documented? I'm wondering if it's just broken and that's why it's not included in this app. Just a shot in the dark.

https://msdn.microsoft.com/EN-US/library/office/jj984330.aspx#sectionSection3

Thanks in advance.

Bill

Tags (1)
0 Karma
1 Solution

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

View solution in original post

0 Karma

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

0 Karma

billford
Path Finder

Well I meant even when I try to retrieve the malware report with a browser via the REST endpoint it is always empty, this is outside the 365 app. I was just wondering if there was some known problem with the endpoint.

If I knew how to write in .net I would totally contribute, I'm sorta porting this over to Python because most of my customers don't have Solunk on Windows.

Thanks

Bill

0 Karma

halr9000
Motivator

@billford, I converted your answer to a comment to keep the Q&A format.

halr9000
Motivator

Paging @gblock

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...