Hi @bbour53 , Thank you for sharing your temp work-around, I've been trying it out since I'm facing this issue as well but somehow it seems it doesn't work every time. Can you kindly confirm that the temp workaround only consists of disabling the message trace input from Splunk Add-On for Microsoft 365 via Web GUI and then re-enabling it instantly or is there a wait time until we re-enable the input? Worked for 1-2 times for me and what I was seeing was that it would make 2 api calls after every 300 secs and the first one would fetch messages but the second one would get the 401 client error and now even the frist one isn't getting any messages.
... View more