<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023 in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/641463#M79047</link>
    <description>&lt;P&gt;I got an update today on the ticket I have open:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Thank you for your patience while we have been working to resolve the issue you reported. We would like to assure you that our engineering team and Microsoft team have been conducting a thorough investigation into the problem.&lt;BR /&gt;&lt;BR /&gt;We are pleased to inform you that the MS team have successfully reproduced the issue locally and is currently implementing patches to prevent reported issues.&lt;BR /&gt;&lt;BR /&gt;As per the latest update from the Microsoft side, They have a new patch being tested and will be rolled out today or the day by tomorrow to Production. ETA for this fix is to be available very soon. If there are any delays, we will update you as soon as possible.&lt;BR /&gt;&lt;BR /&gt;We kindly request your patience as we work to implement this fix. Rest assured that we will update you as soon as we have further information from our engineering team.&lt;BR /&gt;&lt;BR /&gt;Thank you for your understanding and support.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition, my sales engineer indicated that they are having potential success by rolling back to the updated, OAuth version of the Microsoft add-on versus using the Splunk add-on:&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3720" target="_blank"&gt;https://splunkbase.splunk.com/app/3720&lt;/A&gt; instead of&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4055" target="_blank"&gt;https://splunkbase.splunk.com/app/4055&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3720 actually indicates that users should migrate to 4055, but perhaps that's bad advice at the moment. I'm optimistic that they'll fix the 4055 add-on as well though. For now, I'm going to test version 2.0.1 of that first add-on link and I'll report back with my findings.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2023 15:18:16 GMT</pubDate>
    <dc:creator>Wiessiet</dc:creator>
    <dc:date>2023-04-26T15:18:16Z</dc:date>
    <item>
      <title>How can I fix Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/638599#M78857</link>
      <description>&lt;P&gt;Since the first of April we started receiving HTTP 401 Client Error in modular input logs from&amp;nbsp;&lt;SPAN&gt;Splunk Add-on for Microsoft Office 365 Reporting Web Service (TA-MS_O365_Reporting version 2.0.1).&lt;BR /&gt;We tried both OAuth authentication and basic authentication, but we still receive the same error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I was able to replicate the same issue in another Splunk environment against another M365 tenant.&lt;/P&gt;
&lt;P&gt;We also configured the addon Splunk Add-on for Microsoft Office 365 (splunk_ta_o365 version 4.2.1) to fetch these logs, but we still receive the HTTP 401.&lt;/P&gt;
&lt;P&gt;We are pretty confident that the app registrations and permissions are set up correctly.&lt;/P&gt;
&lt;P&gt;Both apps connects to the API endpoint&amp;nbsp;&lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace" target="_blank" rel="noopener"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace&lt;/A&gt;&amp;nbsp;- do anyone know of any changes made to this endpoint from Microsoft?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Rolf&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 17:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/638599#M78857</guid>
      <dc:creator>rvaglid</dc:creator>
      <dc:date>2023-04-26T17:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639042#M78865</link>
      <description>&lt;P&gt;I was glad to find your post - we're having the exact same issue. My first instance of receiving a 401 error for that integration was on 2023-03-31 13:22:20 (Eastern). My O365 administration team pointed me to this posting from Microsoft (looks like you'll need a certain level of access in your tenant to view this) &lt;A href="https://admin.microsoft.com/#/servicehealth/:/alerts/EX537209" target="_blank"&gt;https://admin.microsoft.com/#/servicehealth/:/alerts/EX537209&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;It would seem that this is a Microsoft issue but any kind of information is hard to come by. I hope that's of some use. We're working on reporting it to MS but we're basically in a holding pattern until this works again.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 16:02:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639042#M78865</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-06T16:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639072#M78866</link>
      <description>&lt;P&gt;We do have exactly the same issue. I hope it will get resolved soon.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 19:03:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639072#M78866</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2023-04-06T19:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639189#M78868</link>
      <description>&lt;P&gt;&lt;SPAN&gt;After receiving same error, i have switched from user account to to app account and its working again. Check if app has proper permissions according to:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.michev.info/blog/post/4067/modern-authentication-oauth-support-for-the-reporting-web-ser" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.michev.info/blog/post/4067/modern-authentication-oauth-support-for-the-reporting-web-ser&lt;/A&gt;&lt;SPAN&gt;... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Especially: "Remember that if you are running in the delegate permissions model, the user will need to have an appropriate admin role assigned as well. The supported roles for the Reporting Web Service are Global Reader and Security Reader." &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"ReportingWebService.Read.All for application ones, can only be found under the Office 365 Exchange Online resource. As Microsoft has since hidden the relevant entry under the Request API permissions pane, you will have to follow the instructions from this article to get to it."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After switching to OAuth it went form 401 to 403, and after setting all roles and permissions&amp;nbsp;right from 403 to working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All using following splunk app :&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Splunk Add-on for Microsoft Office 365&lt;/TD&gt;&lt;TD&gt;splunk_ta_o365&lt;/TD&gt;&lt;TD&gt;4.2.1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With input Message Trace.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 09:45:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639189#M78868</guid>
      <dc:creator>LukaszZeszko</dc:creator>
      <dc:date>2023-04-07T09:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639203#M78871</link>
      <description>&lt;P&gt;That's great information. I had reviewed that update to the app and to using OAuth but never got around to implementing. I'm going to test that in my non-production environment today and I'll report back.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 12:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639203#M78871</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-07T12:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639247#M78876</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239698"&gt;@LukaszZeszko&lt;/a&gt;- would you be able to share the permissions you set up to avoid the 403 error? I've gotten stuck there. I have "Office 365 Exchange Online --&amp;gt; ReportingWebService.Read.All" permissions for my application. It seems I need more permissions for this to work but it's unclear to me from the documentation what permissions that should be. Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 19:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639247#M78876</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-07T19:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639512#M78887</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239698"&gt;@LukaszZeszko&lt;/a&gt;&amp;nbsp; - are you currently consuming message trace logs successfully? I implemented this add-on and sorted out my permissions issues and I still get the same 401 error that I got with basic auth:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Basic auth:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-04-10 08:53:50,836 DEBUG pid=2504 tid=MainThread file=connectionpool.py:_make_request:437 | https://reports.office365.com:443 "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2023-03-31T15:51:52.522026Z'%20and%20EndDate%20eq%20datetime'2023-03-31T16:51:52.522026Z' HTTP/1.1" 401 1293

2023-04-10 08:53:50,838 ERROR pid=2504 tid=MainThread file=base_modinput.py:log_error:309 | HTTP Request error: 401 Client Error:  for url: https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2023-03-31T15:51:52.522026Z'%20and%20EndDate%20eq%20datetime'2023-03-31T16:51:52.522026Z'

2023-04-10 08:53:50,839 ERROR pid=2504 tid=MainThread file=base_modinput.py:log_error:309 | Get error when collecting events.&lt;/LI-CODE&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;OAuth:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-04-10 16:36:55,126 level=DEBUG pid=22685 tid=MainThread logger=splunk_ta_o365.modinputs.message_trace pos=__init__.py:_process_messages:298 | datainput=b'XXXX_message_trace' start_time=1681159011 | message="nextLink URL (@odata.nextLink): https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2023-04-09T11%3A00%3A00Z'%20and%20EndDate%20eq%20datetime'2023-04-09T12%3A00%3A00Z'&amp;amp;$skiptoken=1999"

2023-04-10 16:36:55,424 level=ERROR pid=22685 tid=MainThread logger=splunk_ta_o365.modinputs.message_trace pos=__init__.py:_get_messages:253 | datainput=b'XXXX_message_trace' start_time=1681159011 | message="HTTP Request error: 401 Client Error:  for url: https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$filter=StartDate%20eq%20datetime'2023-04-09T11%3A00%3A00Z'%20and%20EndDate%20eq%20datetime'2023-04-09T12%3A00%3A00Z'&amp;amp;$skiptoken=1999" stack_info=True&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 14:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639512#M78887</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-11T14:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639675#M78889</link>
      <description>&lt;P&gt;I am facing the same issue, but according to the link&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240809"&gt;@Wiessiet&lt;/a&gt;&amp;nbsp;posted, it was resolved on April 6th and they are not updating the case information any longer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 17:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639675#M78889</guid>
      <dc:creator>amyers16</dc:creator>
      <dc:date>2023-04-12T17:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639679#M78890</link>
      <description>&lt;P&gt;I saw the same thing yesterday when I went to reference the status. My organization has a ticket open with Microsoft and our O365 team forwarded me the update from a Microsoft engineer that they could replicate the issue. If our ticket bears fruit and I have a worthwhile update for everyone I'll post it here.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 18:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639679#M78890</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-12T18:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639944#M78898</link>
      <description>&lt;P&gt;Anyone have an update on this?&amp;nbsp; We have this issue when using Message Trace inside the Add on for Microsoft Office 365.&amp;nbsp; But the older app Splunk Add On for Microsoft Office 365 Reporting Web Service works.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 13:28:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/639944#M78898</guid>
      <dc:creator>scannon4</dc:creator>
      <dc:date>2023-04-14T13:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640008#M78899</link>
      <description>&lt;P&gt;Throwing my 2-cents in here. We've been using the OAuth route since the beginning of the year without issue. We didn't start seeing the 401 error until 4/7.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the errors started on 4/7, it looked like the error was intermittent and ingestion continued until 4/10, at which point the errors became very persistent.&lt;/P&gt;&lt;P&gt;Disabling the input and re-enabling seemed to have temporarily brought some belief but the issue persists. Sometimes, based on the log, you can see the skiptoken successfully incrementing until it randomly hits the 401. Debug logs show successful retrieval of the access token and Azure AD logs confirm that the app isn't getting any auth failures.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally the consistency of the Microsoft endpoint improves, but maybe the Splunk Add-On for Microsoft Office 365 needs a better method to catch this error and retry instead of starting the collection again at the first message after every failure.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 19:53:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640008#M78899</guid>
      <dc:creator>bbour53</dc:creator>
      <dc:date>2023-04-14T19:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640031#M78901</link>
      <description>&lt;P&gt;Thank you all for your input on this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We managed to get it working again after a great deal of trial and error.&amp;nbsp;&lt;BR /&gt;We ended up creating a brand new service principal, and applying the same permissions again. We had to manually alter the manifest to be able to select "&lt;SPAN&gt;ReportingWebService.Read.All".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Our working theory is that the service principal we have been using for years might be "outdated" in a way, as it started working instantly with a brand new service principal.&lt;BR /&gt;We do not have any information from MS on this theory, as we were able to resolve the issue just before submitting a case to MS.&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Rolf&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 22:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640031#M78901</guid>
      <dc:creator>rvaglid</dc:creator>
      <dc:date>2023-04-14T22:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640370#M78908</link>
      <description>&lt;P&gt;My messaging team said that MS got back to us and the issue is the deprecation of Basic Auth in our tenant. We didn't get any heads up that I was aware of, so it took me by surprise. Unfortunately I've since installed the Splunk Add-on for Microsoft Office 365 (&lt;A href="https://splunkbase.splunk.com/app/4055" target="_blank"&gt;https://splunkbase.splunk.com/app/4055&lt;/A&gt;) and it doesn't work. Using an Azure application with OAuth I still get a 401 error. I've tested the exact same credentials with Postman and they work fine and message trace logs download, so there's something else going on. I have a little more troubleshooting to do and then I'll open a ticket with Splunk as well...&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 15:15:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640370#M78908</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-18T15:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640400#M78909</link>
      <description>&lt;P&gt;I even tried setting up a totally new instance with new app registration and still getting the same error. Not sure that is overly helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 18:06:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640400#M78909</guid>
      <dc:creator>amyers16</dc:creator>
      <dc:date>2023-04-18T18:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640414#M78910</link>
      <description>&lt;P&gt;Same, raising a support ticket with Splunk atm.&lt;/P&gt;&lt;P&gt;Funny thing is the continuous message trace is still running even though it's constantly throwing 401 errors, but only 2000 events at a time and intermittent using all default settings in the input.&lt;/P&gt;&lt;P&gt;Using Azure Enterprise App with ID &amp;amp; Secrets&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 19:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640414#M78910</guid>
      <dc:creator>MightyJ</dc:creator>
      <dc:date>2023-04-18T19:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640417#M78911</link>
      <description>&lt;P&gt;Update from me - I just met with my Splunk support team for something else and made a mention about this. Apparently Splunk is aware and has an internal Jira open. It would appear MS changed something on their side that broke Splunk's TA. I'm going to open a case with Splunk anyway to help with visibility, but this might be a case of having to wait for the two companies to sort it out and fix it &amp;gt;.&amp;lt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 19:30:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640417#M78911</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-18T19:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640509#M78916</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240809"&gt;@Wiessiet&lt;/a&gt;&amp;nbsp;Did they happen to provide an internal reference number or anything? Experiencing the same issue and my support rep hasn’t been able to locate anything internally. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 05:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640509#M78916</guid>
      <dc:creator>grokdesigns</dc:creator>
      <dc:date>2023-04-19T05:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640587#M78920</link>
      <description>&lt;P&gt;They did, the only direct reference they provided was a Jira case: ADDON-61818&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 12:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640587#M78920</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-19T12:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640627#M78926</link>
      <description>&lt;P&gt;That is very helpful, saves us all the time in trying that as a workaround.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 15:18:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640627#M78926</guid>
      <dc:creator>dbot2001</dc:creator>
      <dc:date>2023-04-19T15:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Issues fetching Exchange Online message tracking logs (HTTP 401 Client Error) since 1.4.2023</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640679#M78929</link>
      <description>&lt;P&gt;By way of a further update - I logged a case with Splunk support today and got the following response:&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Thank you for submitting the case.&amp;nbsp;We are aware of this issue and I want to let you know that we have received many cases of the same issue from other customers as well.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;We have reproduced &amp;amp; encountered the same error and suspect an issue with the API, not with the add-on. I would request that you allow us some time to validate the issue from the Microsoft Azure end to know the API behaviour.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;In order to expedite the case, we have escalated the issue to our internal team, and the add-on engineering team has started the conversation with Microsoft about the 401 client error (message trace failure). Rest assured that I will keep you informed of any further updates on this matter.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;I have also associated the internal Jira ticket for this issue with your support case so now even your account owner can check the status for any update from our internal add-on engineering team regarding this.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;If you have any other questions, kindly let me know.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 18:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-can-I-fix-Issues-fetching-Exchange-Online-message-tracking/m-p/640679#M78929</guid>
      <dc:creator>Wiessiet</dc:creator>
      <dc:date>2023-04-19T18:48:04Z</dc:date>
    </item>
  </channel>
</rss>

