# How to check Microsoft 365 service health

**URL:** https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089
**Category:** Beats
**Tags:** beats-module
**Created:** [November 24, 2021, 2:59pm UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089 "2021-11-24T14:59:59Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)
#### Post date: [November 24, 2021, 2:59pm UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/1 "2021-11-24T14:59:59Z")

</div>

Hello experts!  
I have a question - How to check Microsoft 365 service health?  
As far as I know, there is a module for auditing logs in the filebeat. But I would like to get the status of o365 services. Is there such a possibility or perhaps someone has already implemented this case?  
Perhaps this can be done with logstash?

---

<div class="post-metadata">

### Author: ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)
#### Post date: [December 1, 2021, 9:09am UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/2 "2021-12-01T09:09:54Z")

</div>

so far, I have not found modules that will help in solving my problem.  
Now I'm using - http\_poller.  
But this method, in my opinion, requires a preliminary conversion from json to csv, since the state of the services is returned in one message. Any ideas on this?

---

<div class="post-metadata">

### Author: ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)
#### Post date: [December 21, 2021, 9:47am UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/3 "2021-12-21T09:47:00Z")

</div>

I found a workaround how to get partially automatic status from o365. But I have a problem with accessing the ELK database and getting a specific field with a token to form a further request to connect to the api ☹

---

<div class="post-metadata">

### Author: ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)
#### Post date: [December 21, 2021, 12:10pm UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/4 "2021-12-21T12:10:44Z")

</div>

Hi @San9,

If you consider this as a useful feature, feel free to open an improvement issue in the [Beats](https://github.com/elastic/beats) repository. Thanks!

---

<div class="post-metadata">

### Author: ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)
#### Post date: [December 22, 2021, 9:36am UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/5 "2021-12-22T09:36:15Z")

</div>

Hi mtojek!  
Thanks for the answer. For I found a lot of similar overgrowths like mine, but no one could, as far as I understood, perform connections directly due to Authorization and oauth2 problems. It would be nice to implement this, as I think there will be many similar requests. I solved my problem of connecting to the ELK database. I used a different tool and I was able to successfully get a token from the database and use it to connect to o365 and get the status of services. Now I have a problem with the correct parsing of the received message.

```auto
split - Only String and Array types are splittable. field:body is of type = Hash
[DEBUG] 2021-12-22 10:10:04.204 [[main]>worker0] mutate - filters/LogStash::Filters::Mutate: removing field {:field=>"access_token"}

split - Only String and Array types are splittable. field:value is of type = NilClass
[DEBUG] 2021-12-22 10:18:03.359 [[main]>worker0] mutate - filters/LogStash::Filters::Mutate: removing field {:field=>"access_token"}

```

---

<div class="post-metadata">

### Author: ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)
#### Post date: [December 24, 2021, 3:11pm UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/6 "2021-12-24T15:11:03Z")

</div>

I think you need to dig in the Logstash documentation. I remember that there was a config option to drop messages that don't fit the pattern.

---

<div class="post-metadata">

### Author: ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)
#### Post date: [January 11, 2022, 7:53am UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/7 "2022-01-11T07:53:08Z")

</div>

Thanks, I solved this problem

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 8, 2022, 7:53am UTC](https://discuss.elastic.co/t/how-to-check-microsoft-365-service-health/290089/8 "2022-02-08T07:53:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
