<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Office 365 Reporting Add-on not obeying interval configuration in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/558465#M158643</link>
    <description>&lt;P&gt;What is your query window size and delay throttle set at?&amp;nbsp; We had ours at 30 minutes delay throttle and 30 minutes query window size and were seeing drop off of logs every night around 10 pm - midnight.&lt;/P&gt;&lt;P&gt;Over the weekend I updated our config settings to be delay throttle 30 minutes and query window size 60 minutes and it hasn't dropped off for 2 days. Hoping this is a longer term fix, but not holding my breath just yet.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jul 2021 19:09:41 GMT</pubDate>
    <dc:creator>apeadape</dc:creator>
    <dc:date>2021-07-06T19:09:41Z</dc:date>
    <item>
      <title>Microsoft Office 365 Reporting Add-on not obeying interval configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/530462#M149875</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are using version 1.2.4 on Splunk 7.3.7, and we noticed our interval setting of (interval=600 / 10 mins) is not being obeyed. We can see when it does make a successful connection and pull the logs, we see at the start of the connection&amp;nbsp;&lt;FONT&gt;"HTTP connection pooling"&lt;/FONT&gt; in the logs. However, what we see subsequently are continuous connections every minute or so. We tried a splunk restart to see if this made a difference but it hasn't changed it's behaviour. So now we see connections from every 30-40 mins or longer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is an example of the logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;2020-11-23 15:42:12,824 INFO pid=32193 tid=MainThread file=splunk_rest_client.py:_request_handler:105 | Use HTTP connection pooling&lt;BR /&gt;2020-11-23 15:42:12,824 DEBUG pid=32193 tid=MainThread file=binding.py:get:677 | GET request to &lt;A href="https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer&lt;/A&gt; (body: {})&lt;BR /&gt;2020-11-23 15:42:12,826 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_new_conn:959 | Starting new HTTPS connection (1): 127.0.0.1:9001&lt;BR /&gt;2020-11-23 15:42:12,834 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://127.0.0.1:9001" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001&lt;/A&gt; "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/TA_MS_O365_Reporting_checkpointer HTTP/1.1" 200 5509&lt;BR /&gt;2020-11-23 15:42:12,835 DEBUG pid=32193 tid=MainThread file=binding.py:new_f:73 | Operation took 0:00:00.010786&lt;BR /&gt;2020-11-23 15:42:12,836 DEBUG pid=32193 tid=MainThread file=binding.py:get:677 | GET request to &lt;A href="https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/&lt;/A&gt; (body: {'count': -1, 'search': 'TA_MS_O365_Reporting_checkpointer', 'offset': 0})&lt;BR /&gt;2020-11-23 15:42:12,842 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://127.0.0.1:9001" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001&lt;/A&gt; "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/config/?count=-1&amp;amp;search=TA_MS_O365_Reporting_checkpointer&amp;amp;offset=0 HTTP/1.1" 200 7403&lt;BR /&gt;2020-11-23 15:42:12,844 DEBUG pid=32193 tid=MainThread file=binding.py:new_f:73 | Operation took 0:00:00.007860&lt;BR /&gt;2020-11-23 15:42:12,852 DEBUG pid=32193 tid=MainThread file=binding.py:get:677 | GET request to &lt;A href="https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/index_continuously_obj_checkpoint" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/index_continuously_obj_checkpoint&lt;/A&gt; (body: {})&lt;BR /&gt;2020-11-23 15:42:12,857 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://127.0.0.1:9001" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001&lt;/A&gt; "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/index_continuously_obj_checkpoint HTTP/1.1" 200 128&lt;BR /&gt;2020-11-23 15:42:12,857 DEBUG pid=32193 tid=MainThread file=binding.py:new_f:73 | Operation took 0:00:00.005903&lt;BR /&gt;2020-11-23 15:42:12,858 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ Start date: 2020-11-23 14:21:59.057785, End date: 2020-11-23 14:31:59.057785&lt;BR /&gt;2020-11-23 15:42:12,858 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | Endpoint URL: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?\$filter=StartDate" target="_blank" rel="noopener"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?\$filter=StartDate&lt;/A&gt; eq datetime'2020-11-23T14:21:59.057785Z' and EndDate eq datetime'2020-11-23T14:31:59.057785Z'&lt;BR /&gt;2020-11-23 15:42:12,863 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_new_conn:959 | Starting new HTTPS connection (1): reports.office365.com:443&lt;BR /&gt;2020-11-23 15:42:16,000 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://reports.office365.com:443" target="_blank" rel="noopener"&gt;https://reports.office365.com:443&lt;/A&gt; "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?%5C$filter=StartDate%20eq%20datetime'2020-11-23T14:21:59.057785Z'%20and%20EndDate%20eq%20datetime'2020-11-23T14:31:59.057785Z' HTTP/1.1" 200 None&lt;BR /&gt;2020-11-23 15:42:16,073 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ max date before getting message: 2020-11-23 14:21:59.057785&lt;BR /&gt;2020-11-23 15:42:16,893 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ max date after getting messages: 2020-11-23 15:41:50.582546&lt;BR /&gt;2020-11-23 15:42:16,894 DEBUG pid=32193 tid=MainThread file=binding.py:post:750 | POST request to &lt;A href="https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save&lt;/A&gt; (body: {'body': '[{"state": "{\\"max_date\\": \\"2020-11-23 15:41:50.582546\\"}", "_key": "index_continuously_obj_checkpoint"}]'})&lt;BR /&gt;2020-11-23 15:42:16,926 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://127.0.0.1:9001" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001&lt;/A&gt; "POST /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save HTTP/1.1" 200 39&lt;BR /&gt;2020-11-23 15:42:16,928 DEBUG pid=32193 tid=MainThread file=binding.py:new_f:73 | Operation took 0:00:00.033994&lt;BR /&gt;2020-11-23 15:42:16,928 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ nextLink URL (@odata.nextLink): &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=1999" target="_blank" rel="noopener"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=1999&lt;/A&gt;&lt;BR /&gt;2020-11-23 15:42:16,928 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | Endpoint URL: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=1999" target="_blank" rel="noopener"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=1999&lt;/A&gt;&lt;BR /&gt;2020-11-23 15:42:16,932 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_new_conn:959 | Starting new HTTPS connection (1): reports.office365.com:443&lt;BR /&gt;2020-11-23 15:42:18,938 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://reports.office365.com:443" target="_blank" rel="noopener"&gt;https://reports.office365.com:443&lt;/A&gt; "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=1999 HTTP/1.1" 200 None&lt;BR /&gt;2020-11-23 15:42:19,777 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ max date after getting messages: 2020-11-23 15:41:50.582546&lt;BR /&gt;2020-11-23 15:42:19,778 DEBUG pid=32193 tid=MainThread file=binding.py:post:750 | POST request to &lt;A href="https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001/servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save&lt;/A&gt; (body: {'body': '[{"state": "{\\"max_date\\": \\"2020-11-23 15:41:50.582546\\"}", "_key": "index_continuously_obj_checkpoint"}]'})&lt;BR /&gt;2020-11-23 15:42:19,827 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://127.0.0.1:9001" target="_blank" rel="noopener"&gt;https://127.0.0.1:9001&lt;/A&gt; "POST /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/batch_save HTTP/1.1" 200 39&lt;BR /&gt;2020-11-23 15:42:19,829 DEBUG pid=32193 tid=MainThread file=binding.py:new_f:73 | Operation took 0:00:00.051431&lt;BR /&gt;2020-11-23 15:42:19,830 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | _Splunk_ nextLink URL (@odata.nextLink): &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=3999" target="_blank" rel="noopener"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=3999&lt;/A&gt;&lt;BR /&gt;2020-11-23 15:42:19,830 DEBUG pid=32193 tid=MainThread file=base_modinput.py:log_debug:288 | Endpoint URL: &lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=3999" target="_blank" rel="noopener"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=3999&lt;/A&gt;&lt;BR /&gt;2020-11-23 15:42:19,834 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_new_conn:959 | Starting new HTTPS connection (1): reports.office365.com:443&lt;BR /&gt;2020-11-23 15:42:21,872 DEBUG pid=32193 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://reports.office365.com:443" target="_blank" rel="noopener"&gt;https://reports.office365.com:443&lt;/A&gt; "GET /ecp/reportingwebservice/reporting.svc/MessageTrace?$skiptoken=3999&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 16:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/530462#M149875</guid>
      <dc:creator>becksyboy</dc:creator>
      <dc:date>2020-11-23T16:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on not obeying interval configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/557912#M158454</link>
      <description>&lt;P&gt;We are seeing the same thing, did you ever find a solution for this?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 20:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/557912#M158454</guid>
      <dc:creator>apeadape</dc:creator>
      <dc:date>2021-06-30T20:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on not obeying interval configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/558006#M158475</link>
      <description>&lt;P&gt;Hi there, nope we still have the issue. Sometimes it obeys the interval, but it tend to pull in logs at random intervals. We had to write a simple alert to notify us if we don't see any logs after 4 hrs. We still see the c&lt;SPAN&gt;ontinuous connections every minute or so.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 08:09:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/558006#M158475</guid>
      <dc:creator>becksyboy</dc:creator>
      <dc:date>2021-07-01T08:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on not obeying interval configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/558465#M158643</link>
      <description>&lt;P&gt;What is your query window size and delay throttle set at?&amp;nbsp; We had ours at 30 minutes delay throttle and 30 minutes query window size and were seeing drop off of logs every night around 10 pm - midnight.&lt;/P&gt;&lt;P&gt;Over the weekend I updated our config settings to be delay throttle 30 minutes and query window size 60 minutes and it hasn't dropped off for 2 days. Hoping this is a longer term fix, but not holding my breath just yet.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 19:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/558465#M158643</guid>
      <dc:creator>apeadape</dc:creator>
      <dc:date>2021-07-06T19:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Office 365 Reporting Add-on not obeying interval configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/558649#M158707</link>
      <description>&lt;P&gt;Our query size window is set to 10, and delay throttle of 5.&lt;/P&gt;&lt;P&gt;However, below are the actual times data was pulled into Splunk:&lt;/P&gt;&lt;TABLE width="207"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="207"&gt;08/07/2021/05:58:56&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;08/07/2021/04:48:29&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;08/07/2021/04:32:54&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;08/07/2021/02:58:49&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;08/07/2021/01:50:45&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;08/07/2021/00:18:25&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 08 Jul 2021 07:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Microsoft-Office-365-Reporting-Add-on-not-obeying-interval/m-p/558649#M158707</guid>
      <dc:creator>becksyboy</dc:creator>
      <dc:date>2021-07-08T07:37:11Z</dc:date>
    </item>
  </channel>
</rss>

