I am just wondering if others are running into this same issues. I find that some of my sourcetypes mysteriously just stop for a while. They start up again eventually, but we don't really want huge delays in our data.
The azure:aad:signin sourcetype seems to give me the most trouble. Sometimes it may stop for a few hours - but then will immediately provide data if I bounce the input. During this time, I am not even getting debug logs for "source=*ta_ms_aad_MS_AAD_signins.log."
Most recently when I had an issue I noticed a "HTTPError: 504 Server Error: Gateway Timeout for url" for my aad_risk_detection ingest, so I do suspect network issues play a part in the problem. However, that really doesn't address what is happening to the retries...
Microsoft Azure Add-on for Splunk 3.1.1
Splunk Enterprise 8.0.5