Hi, Sounds like the log collection worked for you successfully and then at a later point stopped.
Assuming that's the case, and if the error condition was not transient (and already self resolved), could you verify if these network requirements are in place? https://learn.microsoft.com/en-us/defender-cloud-apps/network-requirements#log-collector.
Also, since you mou mentioned "IP Address of MCAS API URL" - this note at the bottom of that above URL is relevant: If your firewall requires a static IP address access list and does not support allowing based on URL, allow the log collector to initiate outbound traffic to the Microsoft Azure datacenter IP ranges on port 443.