Skip to main content

CollectorsCloud Collectors Administration Guide

Troubleshooting the Microsoft 365 Exchange Admin Reports Cloud Collector

If your Microsoft 365 Exchange Admin Reports cloud collector is not collecting data as expected, or the data collected is incomplete, there could be a problem with the way your Microsoft application is configured to handle message trace information.

The Microsoft 365 Exchange Admin Reports data sources contains valuable raw information about email traffic in your organization. But Microsoft does not collect message trace events by default or analyze the data to generate anomaly and detection events.

To verify that message trace events are being captured properly:

  1. Browse to your Microsoft Exchange portal and navigate to Mail flow > Message trace.

  2. Click Start a trace to launch a new message trace.

  3. Accept the default To and From values and enter a Time Range of two days.

  4. Click Search and verify the results. If the results show missing or incomplete message trace data, refer to the Microsoft guide to enable collection of message trace events in your Microsoft application.

    Note

    If you edit the Microsoft configuration, it may take up to 24 hours before you see a change in the data being collected.