<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft Office 365 Reporting Mail Add-on for Splunk inputs configuration in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537373#M64708</link>
    <description>&lt;P&gt;I have the input working for long time&amp;nbsp;&lt;/P&gt;&lt;P&gt;after it stopped working I have reinstalled the Add-on 1.2.4&lt;/P&gt;&lt;P&gt;Now I am a lot of data I need to import&amp;nbsp;&lt;/P&gt;&lt;P&gt;how you would recommend to setup the input (delay_throttle ,&amp;nbsp;query_window_size ,interval ) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[splunk@ilissplfwd05 local]$ cat inputs.conf&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[ms_o365_message_trace://o365tracking]&lt;BR /&gt;delay_throttle = 720&lt;BR /&gt;index = o365&lt;BR /&gt;input_mode = continuously_monitor&lt;BR /&gt;interval = 30&lt;BR /&gt;office_365_account = o365tracking&lt;BR /&gt;query_window_size = 30&lt;BR /&gt;start_date_time = 2021-01-21T00:00:01&lt;BR /&gt;disabled = 0&lt;BR /&gt;[splunk@ilissplfwd05 local]$&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jan 2021 09:00:28 GMT</pubDate>
    <dc:creator>rayar</dc:creator>
    <dc:date>2021-01-27T09:00:28Z</dc:date>
    <item>
      <title>Microsoft Office 365 Reporting Mail Add-on for Splunk inputs configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537373#M64708</link>
      <description>&lt;P&gt;I have the input working for long time&amp;nbsp;&lt;/P&gt;&lt;P&gt;after it stopped working I have reinstalled the Add-on 1.2.4&lt;/P&gt;&lt;P&gt;Now I am a lot of data I need to import&amp;nbsp;&lt;/P&gt;&lt;P&gt;how you would recommend to setup the input (delay_throttle ,&amp;nbsp;query_window_size ,interval ) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[splunk@ilissplfwd05 local]$ cat inputs.conf&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[ms_o365_message_trace://o365tracking]&lt;BR /&gt;delay_throttle = 720&lt;BR /&gt;index = o365&lt;BR /&gt;input_mode = continuously_monitor&lt;BR /&gt;interval = 30&lt;BR /&gt;office_365_account = o365tracking&lt;BR /&gt;query_window_size = 30&lt;BR /&gt;start_date_time = 2021-01-21T00:00:01&lt;BR /&gt;disabled = 0&lt;BR /&gt;[splunk@ilissplfwd05 local]$&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 09:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537373#M64708</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2021-01-27T09:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Mail Add-on for Splunk inputs configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537395#M64711</link>
      <description>&lt;P&gt;You should be able to do an index once. Can't remember how far you can go back but you should be able to do 20-30 days worth?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ms_o365_message_trace://index_once]&lt;BR /&gt;delay_throttle = 1&lt;BR /&gt;index = ********&lt;BR /&gt;input_mode = index_once&lt;BR /&gt;interval = -1&lt;BR /&gt;office_365_password = ********&lt;BR /&gt;office_365_username = ********&lt;BR /&gt;query_window_size = 60&lt;BR /&gt;start_date_time = 2021-01-01T11:01:01&lt;BR /&gt;end_date_time = 2021-01-27T11:01:01&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 11:18:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537395#M64711</guid>
      <dc:creator>becksyboy</dc:creator>
      <dc:date>2021-01-27T11:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Mail Add-on for Splunk inputs configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537438#M64715</link>
      <description>&lt;P&gt;thanks a lot&lt;/P&gt;&lt;P&gt;I will create a separate input for "Index&amp;nbsp; Once"&lt;/P&gt;&lt;P&gt;What values you would recommend for "Continuously Monitor" ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 15:34:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537438#M64715</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2021-01-27T15:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Mail Add-on for Splunk inputs configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537443#M64716</link>
      <description>&lt;P&gt;This really depends on your requirements. You may want to vary the settings until you find the one that meets your needs.&lt;/P&gt;&lt;P&gt;This may help you:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Input-settings-for-Microsoft-Office-365-Reporting-Add-on-for/m-p/437206#M53764" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Input-settings-for-Microsoft-Office-365-Reporting-Add-on-for/m-p/437206#M53764&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also from the App:&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3720/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/3720/#/details&lt;/A&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Specify the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Query window size (minutes)&lt;/STRONG&gt;. When&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Continuously Monitor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is selected, each time this input runs a start date is calculated for the Office 365 API query. The end date for the Office 365 API query will be the calculated start date plus the number of minutes specified by this parameter. For example, if the calculated start date is 2018-01-01T00:00:00 (midnight on January 1, 2018), the end date for the query will be 2018-01-01T00:01:00 (one hour after midnight) if the query window size is 60 minutes.&lt;/LI&gt;&lt;LI&gt;Specify the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Delay throttle (minutes)&lt;/STRONG&gt;. Microsoft may delay trace events up to 24 hours and events are not guaranteed to be sequential during this delay (&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/office/jj984335.aspx#Anchor_8" target="_blank"&gt;reference&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;). This parameter specifies how close to "now" the end date for a query may be (where "now" is the time that the input runs). Continuing from the example above, if "now" is 2018-01-01T00:02:00 (two minutes after midnight) and the delay throttle is 60 minutes, the input will exit because the end date for the query is only 1 minute away from "now". Each time the input runs, the input will exit and do nothing until the end date is at least 60 minutes away from "now".&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 15:50:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537443#M64716</guid>
      <dc:creator>becksyboy</dc:creator>
      <dc:date>2021-01-27T15:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Mail Add-on for Splunk inputs configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537598#M64727</link>
      <description>&lt;P&gt;This really depends on your requirements. You may want to vary the settings until you find the one that meets your needs.&lt;/P&gt;&lt;P&gt;This may help you:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Input-settings-for-Microsoft-Office-365-Reporting-Add-on-for/m-p/437206#M53764" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Input-settings-for-Microsoft-Office-365-Reporti...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also from the App:&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3720/#/details" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3720/#/details&lt;/A&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Specify the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Query window size (minutes)&lt;/STRONG&gt;. When&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Continuously Monitor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is selected, each time this input runs a start date is calculated for the Office 365 API query. The end date for the Office 365 API query will be the calculated start date plus the number of minutes specified by this parameter. For example, if the calculated start date is 2018-01-01T00:00:00 (midnight on January 1, 2018), the end date for the query will be 2018-01-01T00:01:00 (one hour after midnight) if the query window size is 60 minutes.&lt;/LI&gt;&lt;LI&gt;Specify the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Delay throttle (minutes)&lt;/STRONG&gt;. Microsoft may delay trace events up to 24 hours and events are not guaranteed to be sequential during this delay (&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/office/jj984335.aspx#Anchor_8" target="_blank" rel="nofollow noopener noreferrer"&gt;reference&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;). This parameter specifies how close to "now" the end date for a query may be (where "now" is the time that the input runs). Continuing from the example above, if "now" is 2018-01-01T00:02:00 (two minutes after midnight) and the delay throttle is 60 minutes, the input will exit because the end date for the query is only 1 minute away from "now". Each time the input runs, the input will exit and do nothing until the end date is at least 60 minutes away from "now".&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 28 Jan 2021 10:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Office-365-Reporting-Mail-Add-on-for-Splunk-inputs/m-p/537598#M64727</guid>
      <dc:creator>becksyboy</dc:creator>
      <dc:date>2021-01-28T10:50:36Z</dc:date>
    </item>
  </channel>
</rss>

