All Apps and Add-ons

Splunk TA O365 error loop- How to ask splunk to not go behind and start to collect in time?

marcoRAD
New Member

Hello,

 

i'm experiencing an issue with the splunk TA for O365 and in particular with the Sharepoint Management Activity Logs.

The issue is this:

1) 10:00 AM i activate the input

2) 10:01 AM Splunk starts to collect 10:00 AM events

3) 10:05 AM Splunk continues to collect Sharepoint logs but going behind in time! (9:59 AM, 9:58 AM and so on)

4) 11:00 AM Splunk is still collecting logs in the past but the temporary token expires and the input is closed and reopened

5) 11:00 AM Splunk reopen the input

6) 11:01 AM Splunk starts to collect 11:00 AM events

7) JUMP to step 3 but 1 hour later

 

May you know how to not ask splunk to go behind and starts to collect in time?

 

Regards

 

Marco

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@marcoRAD - On Office 365 App Inputs used to have that option but no longer present in the latest App that I can see.

You can create a Splunk support case to get resolution from the developer of the Add-on.

 

Please consider upvoting/accepting the answer it this helps!!!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...