As @SidHeartsuggested the issue is caused to instability on the old reporting endpoint. Version 6.0.0 onwards of the splunk-add-on-for-microsoft-office-365 TA now introduces a new Ms Graph based message trace input method that should resolve this issue. New Sourcetype: o365:graph:messagetrace TA Documentation describing the update: #https://splunk.github.io/splunk-add-on-for-microsoft-office-365/MigrationGuides/UpdateMessageTraceInput
... View more