Currently there is an Add-On that provides MessageTrace data from O365, is there anything/one out there that is feeding MessageTraceDetail into splunk?
Thanks,
Nathan
Several customers use the add-on to ingest message trace data into Splunk https://splunkbase.splunk.com/app/3720/ . There are a couple of other ways to do it though. One is to use PowerShell cmdlets as a scripted input. Another is to use an Azure automation account and runback. In either of those last 2 cases, you have to keep up with a check point in order to not get duplicate data. The add-on takes care of the check point for you.