# Azure AD (modlue:o365) logs are not fetched consistently by filebeat

**URL:** <https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 14, 2022, 6:12am UTC](https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369 "2022-09-14T06:12:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sriramb12](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sriramb12/32/110719_2.png) [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Post date:** [September 14, 2022, 6:12am UTC](https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369/1 "2022-09-14T06:12:11Z")

</div>

Hi Team  
I am New to the filebeat usage. I am trying to fetch logs from azure tenant using o365 module. I am able to get the logs sometimes but sometimes the expected logs are missing. I expect the logs when there is some tenant activity (sharepoint , admininstrative , exchange etc) . At times, the logs do show up . I tried changing the poll\_interval to 30 sec (from default 3 min) with no luck  
I do see activity on status:

```auto
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
   Loaded: loaded (/usr/lib/systemd/system/filebeat.service; disabled; vendor preset: disabled)
   Active: active (running) since Wed 2022-09-14 10:53:49 IST; 16min ago
     Docs: https://www.elastic.co/beats/filebeat
 Main PID: 32031 (filebeat)
   CGroup: /system.slice/filebeat.service
           └─32031 /usr/share/filebeat/bin/filebeat --environment systemd -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat --path.config /etc/filebeat --path.da...

Sep 14 11:09:30 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:09:30.394+0530","log.logger":"publisher","log.origin":{"file.name"...":"1.6.0"}
Sep 14 11:09:30 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:09:30.394+0530","log.logger":"acker","log.origin":{"file.name":"be...":"1.6.0"}
Sep 14 11:09:30 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:09:30.394+0530","log.logger":"publisher","log.origin":{"file.name"...":"1.6.0"}
Sep 14 11:09:30 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:09:30.394+0530","log.logger":"publisher","log.origin":{"file.name"...":"1.6.0"}
Sep 14 11:09:36 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:09:36.268+0530","log.logger":"cfgfile","log.origin":{"file.name":"...":"1.6.0"}
Sep 14 11:09:46 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:09:46.269+0530","log.logger":"cfgfile","log.origin":{"file.name":"...":"1.6.0"}
Sep 14 11:09:56 crystaleye.lan filebeat[32031]: {"log.level":"info","@timestamp":"2022-09-14T11:09:56.153+0530","log.logger":"monitoring","log.origin":{"file.name"...e":{"ms":1
Sep 14 11:09:56 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:09:56.271+0530","log.logger":"cfgfile","log.origin":{"file.name":"...":"1.6.0"}
Sep 14 11:10:06 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:10:06.271+0530","log.logger":"cfgfile","log.origin":{"file.name":"...":"1.6.0"}
Sep 14 11:10:16 crystaleye.lan filebeat[32031]: {"log.level":"debug","@timestamp":"2022-09-14T11:10:16.272+0530","log.logger":"cfgfile","log.origin":{"file.name":"...":"1.6.0"}
Hint: Some lines were ellipsized, use -l to show in full.

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 14, 2022, 6:19am UTC](https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369/2 "2022-09-14T06:19:52Z")

</div>

You might want to look at `/var/log/filebeat/filebeat.log` to get access to more logs.

---

<div class="post-metadata">

**Author:** ![sriramb12](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sriramb12/32/110719_2.png) [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Post date:** [September 14, 2022, 11:21am UTC](https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369/3 "2022-09-14T11:21:15Z")

</div>

I dont see any files in the /var/log/filebeat/  
Also, say I want to collect historical logs (ex: last 1 month). Is there a way I can use filebeat to get older logs?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2022, 1:21pm UTC](https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369/4 "2022-10-12T13:21:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
