<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure the checkpoint value? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-checkpoint-value/m-p/288606#M34353</link>
    <description>&lt;P&gt;No Answer? I have resolved. &lt;/P&gt;

&lt;P&gt;My event: {"DetailsUrl": "/Orion/NetPerfMon/OrionMessages.aspx?ShowOrionMessageTypes=audit%3b", "AuditEventMessage": "User &lt;EM&gt;**\*&lt;/EM&gt;* logged in from *****&lt;STRONG&gt;&lt;EM&gt;.", "TimeLoggedUtc": "2018-03-29T01:42:32.7370000Z", "DisplayName": "&lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt;\*&lt;/STRONG&gt;**** logged in from *****&lt;STRONG&gt;&lt;EM&gt;.", "NetObjectType": null, "ActionTypeID": 1, "AuditEventID": 3519, "NetworkNode": null, "AccountID": "&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;\*&lt;/EM&gt;****", "NetObjectID": null}&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I have changed my sql like this: &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;SELECT AuditEventID, TimeLoggedUtc, AccountID, ActionTypeID, AuditEventMessage, NetworkNode, NetObjectID, NetObjectType, DetailsUrl, DisplayName FROM Orion.AuditingEvents &lt;STRONG&gt;WHERE TimeLoggedUtc &amp;gt; AddMinute(-10,GETUTCDATE())&lt;/STRONG&gt; order by TimeLoggedUtc DESC&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I am feeling splunk does't find the time automatically. Then I configured TIME_PREFIX. Done
[solarwinds:generic]
TIME_PREFIX = "TimeLoggedUtc":\s"
TIME_FORMAT = %Y-%m-%dT%T.%7N%Z&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Tue, 29 Sep 2020 18:48:51 GMT</pubDate>
    <dc:creator>tdbank</dc:creator>
    <dc:date>2020-09-29T18:48:51Z</dc:date>
    <item>
      <title>How to configure the checkpoint value?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-checkpoint-value/m-p/288605#M34352</link>
      <description>&lt;P&gt;I selected audit event from orion.auditingevents. Then I have follow questions.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;How to configure the checkpoint value in solarwinds query? Because there are too many duplicated events.&lt;/LI&gt;
&lt;LI&gt;If not possible can i use Splunk DB Connect for Solarwinds base? (table: Orion.AuditingEvents)&lt;/LI&gt;
&lt;LI&gt;Audit log time (orion.auditingevents.timeloggedutc) is not equal to indexed time. How can I set audit log time to index time?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 26 Mar 2018 11:19:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-checkpoint-value/m-p/288605#M34352</guid>
      <dc:creator>tdbank</dc:creator>
      <dc:date>2018-03-26T11:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure the checkpoint value?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-checkpoint-value/m-p/288606#M34353</link>
      <description>&lt;P&gt;No Answer? I have resolved. &lt;/P&gt;

&lt;P&gt;My event: {"DetailsUrl": "/Orion/NetPerfMon/OrionMessages.aspx?ShowOrionMessageTypes=audit%3b", "AuditEventMessage": "User &lt;EM&gt;**\*&lt;/EM&gt;* logged in from *****&lt;STRONG&gt;&lt;EM&gt;.", "TimeLoggedUtc": "2018-03-29T01:42:32.7370000Z", "DisplayName": "&lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt;\*&lt;/STRONG&gt;**** logged in from *****&lt;STRONG&gt;&lt;EM&gt;.", "NetObjectType": null, "ActionTypeID": 1, "AuditEventID": 3519, "NetworkNode": null, "AccountID": "&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;\*&lt;/EM&gt;****", "NetObjectID": null}&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I have changed my sql like this: &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;SELECT AuditEventID, TimeLoggedUtc, AccountID, ActionTypeID, AuditEventMessage, NetworkNode, NetObjectID, NetObjectType, DetailsUrl, DisplayName FROM Orion.AuditingEvents &lt;STRONG&gt;WHERE TimeLoggedUtc &amp;gt; AddMinute(-10,GETUTCDATE())&lt;/STRONG&gt; order by TimeLoggedUtc DESC&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I am feeling splunk does't find the time automatically. Then I configured TIME_PREFIX. Done
[solarwinds:generic]
TIME_PREFIX = "TimeLoggedUtc":\s"
TIME_FORMAT = %Y-%m-%dT%T.%7N%Z&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-checkpoint-value/m-p/288606#M34353</guid>
      <dc:creator>tdbank</dc:creator>
      <dc:date>2020-09-29T18:48:51Z</dc:date>
    </item>
  </channel>
</rss>

