I have the input working for long time
after it stopped working I have reinstalled the Add-on 1.2.4
Now I am a lot of data I need to import
how you would recommend to setup the input (delay_throttle , query_window_size ,interval ) ?
[splunk@ilissplfwd05 local]$ cat inputs.conf
[ms_o365_message_trace://o365tracking]
delay_throttle = 720
index = o365
input_mode = continuously_monitor
interval = 30
office_365_account = o365tracking
query_window_size = 30
start_date_time = 2021-01-21T00:00:01
disabled = 0
[splunk@ilissplfwd05 local]$
This really depends on your requirements. You may want to vary the settings until you find the one that meets your needs.
This may help you:
Also from the App:
https://splunkbase.splunk.com/app/3720/#/details
You should be able to do an index once. Can't remember how far you can go back but you should be able to do 20-30 days worth?
[ms_o365_message_trace://index_once]
delay_throttle = 1
index = ********
input_mode = index_once
interval = -1
office_365_password = ********
office_365_username = ********
query_window_size = 60
start_date_time = 2021-01-01T11:01:01
end_date_time = 2021-01-27T11:01:01
thanks a lot
I will create a separate input for "Index Once"
What values you would recommend for "Continuously Monitor" ?
This really depends on your requirements. You may want to vary the settings until you find the one that meets your needs.
This may help you:
Also from the App:
https://splunkbase.splunk.com/app/3720/#/details