All Apps and Add-ons

O365 is configured to send the messagetrace logs are intermittently logged.

gowthambr
New Member

O365 is configured to send the messagetrace logs to splunk heavyforwarder. alt textO365 is configured to send the messagetrace logs are intermittently logged. 0365 team said there is no blocker from their end. O365 is configured to send the messagetrace logs to splunk heavyforwarder. In this case somehow the logs never came to splunk in those gaps. We are trying to understand what happened. I have attached a screenshot which shows a instance where the logging is intermittent. We had reached out to Splunk support with a vendor case and they said that they wont be able to support this as its a community app/add on. The issue continues to occur to this day.

0 Karma

jconger
Splunk Employee
Splunk Employee

Do you see any errors in the _internal index related to this add-on?

index=_internal source="*ta_ms_o365_reporting_ms_o365_message_trace*"

Also, check your input parameters like window size and delay throttle. For more information on what those settings do, check out this post -> https://answers.splunk.com/answers/719725/input-settings-for-microsoft-office-365-reporting.html

0 Karma

patilsonali1729
Path Finder

any update on this?

0 Karma

marycordova
SplunkTrust
SplunkTrust

This Add-on has been pretty reliable for me so this seems pretty odd...

@marycordova
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...