we are facing the same Issue and we found this link but still facing the same issue although we decreased the query_window_size to 5 minutes. https://splunk.my.site.com/customer/s/article/Message-trace-log-ingestion-failure-in-the-Splunk-Add-on-for-Microsoft-Office-365-due-to-too-many-500-error-responses
... View more