Getting Data In

o365 message trace - delay throttle 24 hrs, no bueno - help

angelo
Engager

"The new Office 365 message trace logs have a delay throttle of 24 hours. I believe I understand the reasons behind this decision. Real-time information is important for SOC (Security Operations Center), and having a 24-hour gap in real-time data is a critical issue. One potential solution is to implement two Office 365 add-ons: one configured with the recommended settings and the other with the minimum possible delay time. Does this proposal make sense to anyone, and are there any associated risks?" Thank you for the help. 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @angelo,

I found this issue, but it's withour solution because the problem is in the Microsoft source: they don't want to send report data in real time or with a little delay.

It isn't possible to solve the issue also asking to Splunk PS (I did it).

If you ask to Microsoft they answer: "ask to Splunk"!

because Splunk is a compatitor for they cloud services.

Ciao.

Giuseppe

View solution in original post

angelo
Engager

@gcusello Thank you for the quick reply on this, appreciated. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @angelo,

I found this issue, but it's withour solution because the problem is in the Microsoft source: they don't want to send report data in real time or with a little delay.

It isn't possible to solve the issue also asking to Splunk PS (I did it).

If you ask to Microsoft they answer: "ask to Splunk"!

because Splunk is a compatitor for they cloud services.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...