<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is my Splunk Cloud index filling up with spurious events from ms:o365:management? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298481#M35657</link>
    <description>&lt;P&gt;I am currently evaluating Splunk Cloud for analyzing application logs which we are collecting in Azure Blob Storage.&lt;/P&gt;

&lt;P&gt;I have the Splunk Add-On for Microsoft Cloud Services installed. I currently have a single Storage Account configured, with a single Input using that account. I have not configured any Office 365, or any other account or connector. But I am seeing thousands and thousands of meaningless events of &lt;CODE&gt;sourcetype="ms:o365:management"&lt;/CODE&gt;:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4650i711FDA99F15FDC45/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Where are they coming from?&lt;/P&gt;

&lt;P&gt;How can I stop them being indexed?&lt;/P&gt;

&lt;P&gt;How can I delete them all once I have stopped them being collected?&lt;/P&gt;

&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Mar 2018 21:41:19 GMT</pubDate>
    <dc:creator>davidsykes</dc:creator>
    <dc:date>2018-03-29T21:41:19Z</dc:date>
    <item>
      <title>Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298481#M35657</link>
      <description>&lt;P&gt;I am currently evaluating Splunk Cloud for analyzing application logs which we are collecting in Azure Blob Storage.&lt;/P&gt;

&lt;P&gt;I have the Splunk Add-On for Microsoft Cloud Services installed. I currently have a single Storage Account configured, with a single Input using that account. I have not configured any Office 365, or any other account or connector. But I am seeing thousands and thousands of meaningless events of &lt;CODE&gt;sourcetype="ms:o365:management"&lt;/CODE&gt;:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4650i711FDA99F15FDC45/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Where are they coming from?&lt;/P&gt;

&lt;P&gt;How can I stop them being indexed?&lt;/P&gt;

&lt;P&gt;How can I delete them all once I have stopped them being collected?&lt;/P&gt;

&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 21:41:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298481#M35657</guid>
      <dc:creator>davidsykes</dc:creator>
      <dc:date>2018-03-29T21:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298482#M35658</link>
      <description>&lt;P&gt;Perhaps a Heavy Forwarder is sending this data in to your Splunk Cloud environment.  Click the Hosts tab to see which hosts are sending data, or use a search like below:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=ms* |  stats count by host sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 29 Mar 2018 22:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298482#M35658</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-03-29T22:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298483#M35659</link>
      <description>&lt;P&gt;Thanks for your reply. All of the &lt;CODE&gt;ms*&lt;/CODE&gt; source types are coming from &lt;CODE&gt;127.0.0.1&lt;/CODE&gt;. I am not sure I know exactly what a "Heavy Fowarder" is (I am new to Splunk), but from context I don't think they would show as coming from the localhost, right?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 23:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298483#M35659</guid>
      <dc:creator>davidsykes</dc:creator>
      <dc:date>2018-03-29T23:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298484#M35660</link>
      <description>&lt;P&gt;I will edit the original question to include this information.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 23:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298484#M35660</guid>
      <dc:creator>davidsykes</dc:creator>
      <dc:date>2018-03-29T23:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298485#M35661</link>
      <description>&lt;P&gt;Ok, seems I can't edit my question any more. Oh well.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 23:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298485#M35661</guid>
      <dc:creator>davidsykes</dc:creator>
      <dc:date>2018-03-29T23:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298486#M35662</link>
      <description>&lt;P&gt;What is the source of the data?  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="ms:o365:management" | stats count by source
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This may give some indication on what input is generating the data.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 00:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298486#M35662</guid>
      <dc:creator>ragedsparrow</dc:creator>
      <dc:date>2018-03-30T00:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298487#M35663</link>
      <description>&lt;P&gt;Thanks for the reply. It appears the source is &lt;CODE&gt;eventgen&lt;/CODE&gt;.  Looking this up on &lt;A href="https://splunkbase.splunk.com/app/1924/"&gt;Splunkbase&lt;/A&gt; makes me think this is for generating test data and is definitely something I do not need.&lt;/P&gt;

&lt;P&gt;I will go and disable and/or delete it, if I can figure out how.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 01:24:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298487#M35663</guid>
      <dc:creator>davidsykes</dc:creator>
      <dc:date>2018-03-30T01:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298488#M35664</link>
      <description>&lt;P&gt;It turns my trial Splunk Cloud instance included both &lt;A href="https://splunkbase.splunk.com/app/1924/"&gt;Eventgen&lt;/A&gt; and &lt;A href="https://splunkbase.splunk.com/app/1934/"&gt;Splunk Reference App - PAS&lt;/A&gt;, both of which are intended for app developers and were generating a very large number of events, which were of course no interest to me.&lt;/P&gt;

&lt;P&gt;Thanks to both &lt;CODE&gt;jconger&lt;/CODE&gt; and &lt;CODE&gt;ragedsparrow&lt;/CODE&gt; for pointing me to the source of the events, which led me to figuring out how to disable those apps.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 01:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298488#M35664</guid>
      <dc:creator>davidsykes</dc:creator>
      <dc:date>2018-03-30T01:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298489#M35665</link>
      <description>&lt;P&gt;You can go to the app location:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/etc/apps/Splunk_TA_microsoft-cloudservices/default
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Once you are there, delete eventgen.conf and restart Splunk.&lt;/P&gt;

&lt;P&gt;That should take care of it.  The caveat to that is that you will need to delete it again if you update the app later on.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 02:02:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298489#M35665</guid>
      <dc:creator>ragedsparrow</dc:creator>
      <dc:date>2018-03-30T02:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298490#M35666</link>
      <description>&lt;P&gt;How do I access that in Splunk Cloud?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 02:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298490#M35666</guid>
      <dc:creator>davidsykes</dc:creator>
      <dc:date>2018-03-30T02:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my Splunk Cloud index filling up with spurious events from ms:o365:management?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298491#M35667</link>
      <description>&lt;P&gt;You should be able to disable the Eventgen app under the Manage Apps section.  On the upper left,  you should see the &lt;STRONG&gt;Manage Apps&lt;/STRONG&gt; listed in the Apps drop down.  You should be able to disable the Eventgen app there.  &lt;/P&gt;

&lt;P&gt;You can also access it by going to:&lt;/P&gt;

&lt;P&gt;/en-US/manager/launcher/apps/local&lt;/P&gt;

&lt;P&gt;example: &lt;A href="https://mysplunkinstance.com:8000/en-US/manager/launcher/apps/local"&gt;https://mysplunkinstance.com:8000/en-US/manager/launcher/apps/local&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 04:01:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-my-Splunk-Cloud-index-filling-up-with-spurious-events/m-p/298491#M35667</guid>
      <dc:creator>ragedsparrow</dc:creator>
      <dc:date>2018-03-30T04:01:19Z</dc:date>
    </item>
  </channel>
</rss>

