<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Version 1.1.0 doesn't get message trace in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431145#M52904</link>
    <description>&lt;P&gt;Was this an upgrade or a new install of the add-on?  Also, can you post some more detail from the _internal index?&lt;/P&gt;</description>
    <pubDate>Tue, 29 May 2018 15:26:04 GMT</pubDate>
    <dc:creator>jconger</dc:creator>
    <dc:date>2018-05-29T15:26:04Z</dc:date>
    <item>
      <title>Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431144#M52903</link>
      <description>&lt;P&gt;It seems that there is something wrong with the new version. It doesn't download message trace at all. After copy past url from the log there is an info:&lt;BR /&gt;
There is an unterminated literal at position 102 in 'StartDate eq datetime'2018-05-24T15:52:07.838523Z' and EndDate eq datetime'2018-05-24T16:52:07.838523Z'.&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 13:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431144#M52903</guid>
      <dc:creator>wstarowicz</dc:creator>
      <dc:date>2018-05-29T13:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431145#M52904</link>
      <description>&lt;P&gt;Was this an upgrade or a new install of the add-on?  Also, can you post some more detail from the _internal index?&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 15:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431145#M52904</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-05-29T15:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431146#M52905</link>
      <description>&lt;P&gt;I also just reinstalled the app and still no logs (but URL seems to be fine now).&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 15:08:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431146#M52905</guid>
      <dc:creator>wstarowicz</dc:creator>
      <dc:date>2018-05-30T15:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431147#M52906</link>
      <description>&lt;P&gt;It was an update. See log below (nothing special I think):&lt;/P&gt;

&lt;P&gt;2018-05-30 14:55:01,287 DEBUG pid=24525 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.002906&lt;BR /&gt;
2018-05-30 14:55:01,287 DEBUG pid=24525 tid=MainThread file=base_modinput.py:log_debug:286 | Start date: 2018-05-25 15:46:10.659534, End date: 2018-05-25 16:46:10.659534&lt;BR /&gt;
2018-05-30 14:55:01,287 DEBUG pid=24525 tid=MainThread file=base_modinput.py:log_debug:286 | Endpoint URL: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate" target="_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate&lt;/A&gt; eq datetime'2018-05-25T15:46:10.659534Z' and EndDate eq datetime'2018-05-25T16:46:10.659534Z'&lt;BR /&gt;
2018-05-30 14:55:01,288 INFO pid=24525 tid=MainThread file=setup_util.py:log_info:114 | Proxy is not enabled!&lt;BR /&gt;
2018-05-30 14:55:01,291 DEBUG pid=24525 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): reports.office365.com&lt;BR /&gt;
2018-05-30 14:55:07,405 DEBUG pid=24525 tid=MainThread file=connectionpool.py:_make_request:400 | &lt;A href="https://reports.office365.com:443" target="_blank"&gt;https://reports.office365.com:443&lt;/A&gt; "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2018-05-25T15:46:10.659534Z'%20and%20EndDate%20eq%20datetime'2018-05-25T16:46:10.659534Z' HTTP/1.1" 200 None&lt;BR /&gt;
2018-05-30 14:55:07,613 DEBUG pid=24525 tid=MainThread file=base_modinput.py:log_debug:286 | Number of messages returned: 1696&lt;BR /&gt;
2018-05-30 14:55:07,613 DEBUG pid=24525 tid=MainThread file=base_modinput.py:log_debug:286 | Max date before getting message: 2018-05-25 15:46:10.659534&lt;BR /&gt;
2018-05-30 14:55:08,013 DEBUG pid=24525 tid=MainThread file=base_modinput.py:log_debug:286 | Max date after getting messages: 2018-05-25 16:46:10.035204&lt;BR /&gt;
2018-05-30 14:55:08,014 DEBUG pid=24525 tid=MainThread file=binding.py:post:736 | POST request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save&lt;/A&gt; (body: {'body': '[{"state": "{\"max_date\": \"2018-05-25 16:46:10.035204\"}", "_key": "msgtrace_obj_checkpoint"}]'})&lt;BR /&gt;
2018-05-30 14:55:08,051 DEBUG pid=24525 tid=MainThread file=connectionpool.py:_make_request:387 | "POST /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save HTTP/1.1" 200 29&lt;BR /&gt;
2018-05-30 14:55:08,052 DEBUG pid=24525 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.038370&lt;BR /&gt;
2018-05-30 15:54:57,332 INFO pid=30681 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2018-05-30 15:54:58,204 INFO pid=30681 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2018-05-30 15:54:59,693 INFO pid=30681 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2018-05-30 15:55:01,155 INFO pid=30681 tid=MainThread file=splunk_rest_client.py:_request_handler:100 | Use HTTP connection pooling&lt;BR /&gt;
2018-05-30 15:55:01,155 DEBUG pid=30681 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer&lt;/A&gt; (body: {})&lt;BR /&gt;
2018-05-30 15:55:01,156 INFO pid=30681 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2018-05-30 15:55:01,160 DEBUG pid=30681 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer HTTP/1.1" 200 5516&lt;BR /&gt;
2018-05-30 15:55:01,161 DEBUG pid=30681 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.005667&lt;BR /&gt;
2018-05-30 15:55:01,161 DEBUG pid=30681 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/&lt;/A&gt; (body: {'offset': 0, 'search': 'TA_MS_O365_Reporting_checkpointer', 'count': -1})&lt;BR /&gt;
2018-05-30 15:55:01,166 DEBUG pid=30681 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/?offset=0&amp;amp;search=TA_MS_O365_Reporting_checkpointer&amp;amp;count=-1 HTTP/1.1" 200 7417&lt;BR /&gt;
2018-05-30 15:55:01,166 DEBUG pid=30681 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.004694&lt;BR /&gt;
2018-05-30 15:55:01,168 DEBUG pid=30681 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/msgtrace_obj_checkpoint" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/msgtrace_obj_checkpoint&lt;/A&gt; (body: {})&lt;BR /&gt;
2018-05-30 15:55:01,171 DEBUG pid=30681 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/msgtrace_obj_checkpoint HTTP/1.1" 200 118&lt;BR /&gt;
2018-05-30 15:55:01,171 DEBUG pid=30681 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.003147&lt;BR /&gt;
2018-05-30 15:55:01,172 DEBUG pid=30681 tid=MainThread file=base_modinput.py:log_debug:286 | Start date: 2018-05-25 16:46:10.035204, End date: 2018-05-25 17:46:10.035204&lt;BR /&gt;
2018-05-30 15:55:01,172 DEBUG pid=30681 tid=MainThread file=base_modinput.py:log_debug:286 | Endpoint URL: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate" target="_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate&lt;/A&gt; eq datetime'2018-05-25T16:46:10.035204Z' and EndDate eq datetime'2018-05-25T17:46:10.035204Z'&lt;BR /&gt;
2018-05-30 15:55:01,172 INFO pid=30681 tid=MainThread file=setup_util.py:log_info:114 | Proxy is not enabled!&lt;BR /&gt;
2018-05-30 15:55:01,175 DEBUG pid=30681 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): reports.office365.com&lt;BR /&gt;
2018-05-30 15:55:07,207 DEBUG pid=30681 tid=MainThread file=connectionpool.py:_make_request:400 | &lt;A href="https://reports.office365.com:443" target="_blank"&gt;https://reports.office365.com:443&lt;/A&gt; "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2018-05-25T16:46:10.035204Z'%20and%20EndDate%20eq%20datetime'2018-05-25T17:46:10.035204Z' HTTP/1.1" 200 None&lt;BR /&gt;
2018-05-30 15:55:07,990 DEBUG pid=30681 tid=MainThread file=base_modinput.py:log_debug:286 | Number of messages returned: 1631&lt;BR /&gt;
2018-05-30 15:55:07,990 DEBUG pid=30681 tid=MainThread file=base_modinput.py:log_debug:286 | Max date before getting message: 2018-05-25 16:46:10.035204&lt;BR /&gt;
2018-05-30 15:55:08,380 DEBUG pid=30681 tid=MainThread file=base_modinput.py:log_debug:286 | Max date after getting messages: 2018-05-25 17:46:04.759034&lt;BR /&gt;
2018-05-30 15:55:08,380 DEBUG pid=30681 tid=MainThread file=binding.py:post:736 | POST request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save&lt;/A&gt; (body: {'body': '[{"state": "{\"max_date\": \"2018-05-25 17:46:04.759034\"}", "_key": "msgtrace_obj_checkpoint"}]'})&lt;BR /&gt;
2018-05-30 15:55:08,399 DEBUG pid=30681 tid=MainThread file=connectionpool.py:_make_request:387 | "POST /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save HTTP/1.1" 200 29&lt;BR /&gt;
2018-05-30 15:55:08,400 DEBUG pid=30681 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.019649&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:47:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431147#M52906</guid>
      <dc:creator>wstarowicz</dc:creator>
      <dc:date>2020-09-29T19:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431148#M52907</link>
      <description>&lt;P&gt;The debug logs above indicate that message traces are being returned by the text "Number of messages returned: 1631".  The input is polling for an hour's worth of data is seems by comparing the max date before and after the input runs.  Are you searching your index for "All Time"?  The data collection started a few days back and is pulling in an hour's worth of data each run, so there will be some catch up time.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 14:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431148#M52907</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-05-31T14:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431149#M52908</link>
      <description>&lt;P&gt;Ok, so I assume that first it has to download all older message traces. &lt;BR /&gt;
I also just checked 'All Time' and there are events with date i.e. "31/05/2018 12:05:02.614" - I do not know why it doesn't show in last 24h.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 11:14:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431149#M52908</guid>
      <dc:creator>wstarowicz</dc:creator>
      <dc:date>2018-06-01T11:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431150#M52909</link>
      <description>&lt;P&gt;Actually the question is: what do you think are the optimum values for Query window size and Delay throttle to get "almost" realtime traces?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 12:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431150#M52909</guid>
      <dc:creator>wstarowicz</dc:creator>
      <dc:date>2018-06-01T12:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431151#M52910</link>
      <description>&lt;P&gt;I had the same issue after upgrading to the new app, it would query upto last 6days and when it come to last 24hrs the input fails with error "end_date is greater than the specified delay throttle [start_date=2018-05-30 23:08:16.241651 end_date=2018-05-31 00:08:16.241651 utc_now=2018-05-31 23:53:58.493033] Skipping..."&lt;/P&gt;

&lt;P&gt;I used the default values since i did not knew what values I need to set.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431151#M52910</guid>
      <dc:creator>shirishkamat84</dc:creator>
      <dc:date>2020-09-29T19:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431152#M52911</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;

&lt;P&gt;Had the same issues, but i played around with the settings and found something that worked for me:&lt;/P&gt;

&lt;P&gt;Interval: 300 seconds&lt;BR /&gt;
Query windows size: 30 minutes&lt;BR /&gt;
Delay throttle: 32 minutes&lt;/P&gt;

&lt;P&gt;Probably not optimal settings, but at least it works better than the default values &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 08:38:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431152#M52911</guid>
      <dc:creator>snrnbrem</dc:creator>
      <dc:date>2018-06-11T08:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431153#M52912</link>
      <description>&lt;P&gt;Hello, confirm it.&lt;BR /&gt;
Re-create inputs with your parameters - all work.But If change back - nothing work.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 09:21:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431153#M52912</guid>
      <dc:creator>templier</dc:creator>
      <dc:date>2018-06-13T09:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431154#M52913</link>
      <description>&lt;P&gt;Use this:&lt;BR /&gt;
Interval: 300 seconds&lt;BR /&gt;
Query windows size: 30 minutes&lt;BR /&gt;
Delay throttle: 32 minutes&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 14:15:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431154#M52913</guid>
      <dc:creator>templier</dc:creator>
      <dc:date>2018-06-13T14:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431155#M52914</link>
      <description>&lt;P&gt;Has there been any word from Splunk as to what the optimal settings should be?  It's strange that the default numbers for the configs throw errors and doesn't return actual results.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 16:17:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431155#M52914</guid>
      <dc:creator>JScordo</dc:creator>
      <dc:date>2018-07-24T16:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431156#M52915</link>
      <description>&lt;P&gt;Hello, &lt;BR /&gt;
Have't information from Splunk.&lt;BR /&gt;
In first release all work fine with a default value, but after update we hade trouble.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 06:17:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431156#M52915</guid>
      <dc:creator>templier</dc:creator>
      <dc:date>2018-07-25T06:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431157#M52916</link>
      <description>&lt;P&gt;Same issue here, after upgrading we no longer are getting message trace logs. Has anyone been able to fix this?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 10:20:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431157#M52916</guid>
      <dc:creator>bcatoe112</dc:creator>
      <dc:date>2018-08-01T10:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431158#M52917</link>
      <description>&lt;P&gt;jconger [Splunk]&lt;/P&gt;

&lt;P&gt;Will a newer version be [re]released any time soon?  I see some on the forum mentioning 1.1.3, when splunkbase only has 1.1.0.&lt;/P&gt;

&lt;P&gt;I ask, because like several others, a fresh install of 1.1.0 is getting 404 for the data in continuous mode.  When I tried an index-once, it successfully downloaded ~2 weeks of events.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-10-02 16:57:10,598 DEBUG pid=7676 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer" target="test_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer&lt;/A&gt; (body: {})
2018-10-02 16:57:10,599 INFO pid=7676 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1
2018-10-02 16:57:10,602 DEBUG pid=7676 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer HTTP/1.1" 200 5516
2018-10-02 16:57:10,604 DEBUG pid=7676 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.005000
2018-10-02 16:57:10,604 DEBUG pid=7676 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/" target="test_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/&lt;/A&gt; (body: {'search': 'TA_MS_O365_Reporting_checkpointer', 'count': -1, 'offset': 0})
2018-10-02 16:57:10,605 DEBUG pid=7676 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/?search=TA_MS_O365_Reporting_checkpointer&amp;amp;count=-1&amp;amp;offset=0 HTTP/1.1" 200 7407
2018-10-02 16:57:10,607 DEBUG pid=7676 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.003000
2018-10-02 16:57:10,611 DEBUG pid=7676 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/MYORG_continuous_obj_checkpoint" target="test_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/MYORG_continuous_obj_checkpoint&lt;/A&gt; (body: {})
2018-10-02 16:57:10,614 DEBUG pid=7676 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/MYORG_continuous_obj_checkpoint HTTP/1.1" 404 140
2018-10-02 16:57:10,615 DEBUG pid=7676 tid=MainThread file=base_modinput.py:log_debug:286 | Start date: 2018-10-01 00:00:00, End date: 2018-10-01 00:30:00
2018-10-02 16:57:10,615 DEBUG pid=7676 tid=MainThread file=base_modinput.py:log_debug:286 | Endpoint URL: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate" target="test_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate&lt;/A&gt; eq datetime'2018-10-01T00:00:00Z' and EndDate eq datetime'2018-10-01T00:30:00Z'
2018-10-02 16:57:10,615 INFO pid=7676 tid=MainThread file=setup_util.py:log_info:114 | Proxy is not enabled!
2018-10-02 16:57:10,619 DEBUG pid=7676 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): reports.office365.com
2018-10-02 16:57:10,974 DEBUG pid=7676 tid=MainThread file=connectionpool.py:_make_request:400 | &lt;A href="https://reports.office365.com:443" target="test_blank"&gt;https://reports.office365.com:443&lt;/A&gt; "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2018-10-01T00:00:00Z'%20and%20EndDate%20eq%20datetime'2018-10-01T00:30:00Z' HTTP/1.1" 404 115
2018-10-02 16:57:10,979 ERROR pid=7676 tid=MainThread file=base_modinput.py:log_error:307 | HTTP Request error: 404 Client Error: Not Found for url: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2018-10-01T00:00:00Z'%20and%20EndDate%20eq%20datetime'2018-10-01T00:30:00Z'" target="test_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2018-10-01T00:00:00Z'%20and%20EndDate%20eq%20datetime'2018-10-01T00:30:00Z'&lt;/A&gt;;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Oct 2018 00:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431158#M52917</guid>
      <dc:creator>ChrisBell04</dc:creator>
      <dc:date>2018-10-03T00:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431159#M52918</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;even with those settings I am still seeing the error:&lt;/P&gt;

&lt;P&gt;Interval: 300 seconds&lt;BR /&gt;
Query windows size: 30 minutes&lt;BR /&gt;
Delay throttle: 32 minutes&lt;/P&gt;

&lt;P&gt;2019-04-02 11:38:32,983 DEBUG pid=7604 tid=MainThread file=base_modinput.py:log_debug:286 | end_date is greater than the specified delay throttle [start_date=2019-04-02 14:49:40.649092 end_date=2019-04-02 15:19:40.649092 utc_now=2019-04-02 15:38:32.983000] Skipping...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:55:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431159#M52918</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2020-09-29T23:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Version 1.1.0 doesn't get message trace</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431160#M52919</link>
      <description>&lt;P&gt;i am facing the same issue? anyone have fix for above issue?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 11:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Version-1-1-0-doesn-t-get-message-trace/m-p/431160#M52919</guid>
      <dc:creator>martinnepolean</dc:creator>
      <dc:date>2020-03-03T11:54:59Z</dc:date>
    </item>
  </channel>
</rss>

