Getting Data In

O365 Message trace logs into Splunk

anandhalagarasa
Path Finder

Hi Team,

We have a request to index the O365 Message trace logs from Splunk .

So as recommended in Splunk blog we have followed the 1st step to retrieve the same.

https://www.splunk.com/blog/2017/10/05/splunking-microsoft-cloud-data-part-3.html

-->We have installed the Microsoft Office365 Reporting Add-on
-->As mentioned in the blog we have updated the configuration and their respective inputs.

Post which when we tried to fetch the logs with sourcetype as ms:o365:reporting:messagetrace we can able to see some events which got generated on Jan 12th 2018 and post which we couldn't able to see any new events for the same.

We are not sure about the exact issue in it.

We have provided the inputs and configurations as recommended. And I can able to see the logs for just one day and that means logs are getting ingested but dont know why it got indexed only for one day and post which there are no logs.

So kindly help on my query.

Tags (1)
0 Karma

maciep
Champion

i have no answer for you, but i think we could use that add-on. If I end up trying to install it, I'll share my experience.

0 Karma

anandhalagarasa
Path Finder

Kindly share your comments

0 Karma

anandhalagarasa
Path Finder

can anyone help on my request

0 Karma

anandhalagarasa
Path Finder

can anyone respond

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...