<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/507841#M62382</link>
    <description>&lt;P&gt;Have you by chance found the solution for this? I've run into this a couple of times with version 1.2.0 on Splunk v8. I bounce the input similar to as described in the original post, the only error I see is:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid=21847&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tid=MainThread&lt;/SPAN&gt; &lt;SPAN class="t"&gt;file=base_modinput.py:log_error:309&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class="t"&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Request&lt;/SPAN&gt; &lt;SPAN class="t"&gt;error:&lt;/SPAN&gt;&lt;SPAN&gt; ("&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;broken:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ConnectionResetError&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;104&lt;/SPAN&gt;&lt;SPAN&gt;, '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;reset&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;peer&lt;/SPAN&gt;&lt;SPAN&gt;')", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ConnectionResetError&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;104&lt;/SPAN&gt;&lt;SPAN&gt;, '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;reset&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;peer&lt;/SPAN&gt;&lt;SPAN&gt;'))&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jul 2020 13:27:28 GMT</pubDate>
    <dc:creator>_joe</dc:creator>
    <dc:date>2020-07-07T13:27:28Z</dc:date>
    <item>
      <title>Microsoft Office 365 Reporting Add-on for Splunk is Unstable- Anyone else experiencing this issue?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469214#M57687</link>
      <description>&lt;P&gt;We are using version 1.1 of Microsoft Office 365 Reporting Add-on for Splunk, but the app stops pulling the data very often, and there aren't any error messages at all from internal logs. We have to disable and enable the account manually from the inputs, and the app starts pulling the data. Does anyone encounter this kind of issue? And what is the better solution to fix this issue? Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469214#M57687</guid>
      <dc:creator>lucas4394</dc:creator>
      <dc:date>2022-03-10T19:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469215#M57688</link>
      <description>&lt;P&gt;I have experienced this as well. We've only been using it for a short time, so I can't speak to frequency yet. I found the python process responsible for the input was stuck on the heavy forwarder. I killed it with a HUP and it restarted properly and back-filled the data.&lt;/P&gt;

&lt;P&gt;Next time it happens I'll try to get deeper into where it is stuck. If I can't figure it out, I'll look to build a watchdog of sorts to kill it when stale.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 04:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469215#M57688</guid>
      <dc:creator>madcitygeek</dc:creator>
      <dc:date>2019-10-29T04:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469216#M57689</link>
      <description>&lt;P&gt;Same issue here.&lt;BR /&gt;
It &lt;EM&gt;seems&lt;/EM&gt; to correlate with network issues/server reboots.&lt;BR /&gt;
Haven't been able to pin it down yet. My workaround is to add a new input each time and kill the old one.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 05:44:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469216#M57689</guid>
      <dc:creator>joshschwarz</dc:creator>
      <dc:date>2019-10-29T05:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469217#M57690</link>
      <description>&lt;P&gt;So here is an interesting twist with this app (Microsoft Office 365 Reporting Add-on for Splunk)  We have been using it for over a year with no issues.  All of a sudden, we started getting a 500 Internal Server error when we pull the data.  We contacted Microsoft and this method of pulling down message trace is not supported by Microsoft and is not even guaranteed to work in the future.&lt;/P&gt;

&lt;P&gt;So, does anyone else have a reliable method for pulling in message trace data into Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 13:25:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469217#M57690</guid>
      <dc:creator>scannon4</dc:creator>
      <dc:date>2019-10-30T13:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469218#M57691</link>
      <description>&lt;P&gt;Same error here as well -  HTTP Request error: 500 Server Error: Internal Server Error for url: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc&lt;/A&gt; .  &lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 18:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469218#M57691</guid>
      <dc:creator>dharma891</dc:creator>
      <dc:date>2019-10-30T18:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469219#M57692</link>
      <description>&lt;P&gt;Yes, this was the same solution placed into my environment as well.  Hopefully, Microsoft will fix this issue in the near future.  Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 13:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469219#M57692</guid>
      <dc:creator>lucas4394</dc:creator>
      <dc:date>2019-10-31T13:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469220#M57693</link>
      <description>&lt;P&gt;For the 500 error, you might want to go to this post and up-vote.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/780097/microsoft-office-365-reporting-add-on-for-splunk-n.html"&gt;https://answers.splunk.com/answers/780097/microsoft-office-365-reporting-add-on-for-splunk-n.html&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 16:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469220#M57693</guid>
      <dc:creator>psalm_splunk</dc:creator>
      <dc:date>2019-11-04T16:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469221#M57694</link>
      <description>&lt;P&gt;For the 500 error, you might want to go to this post and up-vote.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/780097/microsoft-office-365-reporting-add-on-for-splunk-n.html"&gt;https://answers.splunk.com/answers/780097/microsoft-office-365-reporting-add-on-for-splunk-n.html&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 16:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/469221#M57694</guid>
      <dc:creator>psalm_splunk</dc:creator>
      <dc:date>2019-11-04T16:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/507841#M62382</link>
      <description>&lt;P&gt;Have you by chance found the solution for this? I've run into this a couple of times with version 1.2.0 on Splunk v8. I bounce the input similar to as described in the original post, the only error I see is:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid=21847&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tid=MainThread&lt;/SPAN&gt; &lt;SPAN class="t"&gt;file=base_modinput.py:log_error:309&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class="t"&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Request&lt;/SPAN&gt; &lt;SPAN class="t"&gt;error:&lt;/SPAN&gt;&lt;SPAN&gt; ("&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;broken:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ConnectionResetError&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;104&lt;/SPAN&gt;&lt;SPAN&gt;, '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;reset&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;peer&lt;/SPAN&gt;&lt;SPAN&gt;')", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ConnectionResetError&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;104&lt;/SPAN&gt;&lt;SPAN&gt;, '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;reset&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;peer&lt;/SPAN&gt;&lt;SPAN&gt;'))&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 13:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/507841#M62382</guid>
      <dc:creator>_joe</dc:creator>
      <dc:date>2020-07-07T13:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/513883#M62929</link>
      <description>&lt;P&gt;I only wanted to additionally comment, we are up to version 1.2.1 now and this TA still appears to be unstable.&lt;/P&gt;&lt;P&gt;For me, most of the problems absolutely stem from network and connection issues. My location does have intermittent WAN issues, no denying that. The problem is, 24 hours later, the TA still cannot recover from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I find that enabling and disabling the input from the web UI is the smallest action to correct the problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am considering scripting a restart of Splunk but that just seems silly. Are other people still having issues with this TA, and how have you found to be the most eloquent way to deal with them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 11:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/513883#M62929</guid>
      <dc:creator>_joe</dc:creator>
      <dc:date>2020-08-13T11:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/522274#M63631</link>
      <description>&lt;P&gt;This thread has a working solution:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-not-pulling/m-p/513855/highlight/false#M62927" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-not-pulling/m-p/513855/highlight/false#M62927&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224870"&gt;@poisar&lt;/a&gt; opened a case with MS and adding a \ before the $filter in the script solved the problem for me&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 14:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/522274#M63631</guid>
      <dc:creator>gordo32</dc:creator>
      <dc:date>2020-09-30T14:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/531487#M64328</link>
      <description>&lt;DIV&gt;On version 1.2.4 on Splunk 7.3.7. We had applied the suggested fix of adding a \ before the $filter. But we are faced with two issues.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;[1] The connection interval is not being obeyed. We have it set to 10 mins, but our logs seems to be continuously updated like the connection hasn't completed.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;2020-12-01 10:21:10.854&lt;BR /&gt;2020-12-01 10:21:10,854 DEBUG pid=28567 tid=MainThread file=connectionpool.py:_new_conn:959 | Starting new HTTPS connection (1): reports.office365.com:443&lt;BR /&gt;2020-12-01 10:21:10.850&lt;BR /&gt;2020-12-01 10:21:10,850 DEBUG pid=28567 tid=MainThread file=base_modinput.py:log_debug:288 | Endpoint URL: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=413999" target="_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=413999&lt;/A&gt;&lt;BR /&gt;2020-12-01 10:21:10.850&lt;BR /&gt;2020-12-01 10:21:10,850 DEBUG pid=28567 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ nextLink URL (@odata.nextLink): &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=413999" target="_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=413999&lt;/A&gt;&lt;BR /&gt;2020-12-01 10:21:10.850&lt;BR /&gt;2020-12-01 10:21:10,850 DEBUG pid=28567 tid=MainThread file=binding.py:new_f:73 | Operation took 0:00:00.022766&lt;BR /&gt;2020-12-01 10:21:10.848&lt;BR /&gt;2020-12-01 10:21:10,848 DEBUG pid=28567 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://127.0.0.1:9001" target="_blank"&gt;https://127.0.0.1:9001&lt;/A&gt; "POST /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save HTTP/1.1" 200 39&lt;BR /&gt;2020-12-01 10:21:10.827&lt;BR /&gt;2020-12-01 10:21:10,827 DEBUG pid=28567 tid=MainThread file=binding.py:post:750 | POST request to &lt;A href="https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save" target="_blank"&gt;https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save&lt;/A&gt; (body: {'body': '[{"_key": "index_continuously_obj_checkpoint", "state": "{\\"max_date\\": \\"2020-12-01 09:54:07.121067\\"}"}]'})&lt;BR /&gt;2020-12-01 10:21:10.827&lt;BR /&gt;2020-12-01 10:21:10,827 DEBUG pid=28567 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ max date after getting messages: 2020-12-01 09:54:07.121067&lt;BR /&gt;2020-12-01 10:21:09.913&lt;BR /&gt;2020-12-01 10:21:09,913 DEBUG pid=28567 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://reports.office365.com:443" target="_blank"&gt;https://reports.office365.com:443&lt;/A&gt; "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=411999 HTTP/1.1" 200 None&lt;BR /&gt;2020-12-01 10:21:21.866&lt;BR /&gt;2020-12-01 10:21:21,866 DEBUG pid=28567 tid=MainThread file=connectionpool.py:_new_conn:959 | Starting new HTTPS connection (1): reports.office365.com:443&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;[2] When we do have a successful connection that pulls logs (happens every 1-2 hours) we get these errors:&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;HTTPError: 500 Server Error: Internal Server Error for url: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=999999" target="_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=999999&lt;/A&gt;&lt;BR /&gt;2020-12-01 09:53:50,446 ERROR pid=13324 tid=MainThread file=base_modinput.py:log_error:309 | Get error when collecting events.&lt;BR /&gt;2020-12-01 09:53:50,440 ERROR pid=13324 tid=MainThread file=base_modinput.py:log_error:309 | HTTP Request error: 500 Server Error: Internal Server Error for url: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=999999" target="_blank"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=999999&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 01 Dec 2020 10:27:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/531487#M64328</guid>
      <dc:creator>becksyboy</dc:creator>
      <dc:date>2020-12-01T10:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on for Splunk is Unstable</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/588484#M76310</link>
      <description>&lt;P&gt;I haven't seen this behaviour. Did you change *boht* lines that contain $filter ??&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:20:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Add-on-for-Splunk-is-Unstable/m-p/588484#M76310</guid>
      <dc:creator>gordo32</dc:creator>
      <dc:date>2022-03-10T19:20:38Z</dc:date>
    </item>
  </channel>
</rss>

