All Apps and Add-ons

O365 is configured to send the messagetrace logs are intermittently logged.

gowthambr
New Member

O365 is configured to send the messagetrace logs to splunk heavyforwarder. alt textO365 is configured to send the messagetrace logs are intermittently logged. 0365 team said there is no blocker from their end. O365 is configured to send the messagetrace logs to splunk heavyforwarder. In this case somehow the logs never came to splunk in those gaps. We are trying to understand what happened. I have attached a screenshot which shows a instance where the logging is intermittent. We had reached out to Splunk support with a vendor case and they said that they wont be able to support this as its a community app/add on. The issue continues to occur to this day.

0 Karma

jconger
Splunk Employee
Splunk Employee

Do you see any errors in the _internal index related to this add-on?

index=_internal source="*ta_ms_o365_reporting_ms_o365_message_trace*"

Also, check your input parameters like window size and delay throttle. For more information on what those settings do, check out this post -> https://answers.splunk.com/answers/719725/input-settings-for-microsoft-office-365-reporting.html

0 Karma

patilsonali1729
Path Finder

any update on this?

0 Karma

marycordova
SplunkTrust
SplunkTrust

This Add-on has been pretty reliable for me so this seems pretty odd...

@marycordova
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...