<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [SailPoint] Get older events in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/SailPoint-Get-older-events/m-p/763056#M11165</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enabled the app&amp;nbsp;SailPoint Identity Security Cloud AuditEvent but I'd like to ingest older event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no option in the configuration (I think) to set the time range on which the Splunk app gather events.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone faced the same issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;</description>
    <pubDate>Fri, 21 Aug 2026 14:53:13 GMT</pubDate>
    <dc:creator>MandarinDefense</dc:creator>
    <dc:date>2026-08-21T14:53:13Z</dc:date>
    <item>
      <title>[SailPoint] Get older events</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/SailPoint-Get-older-events/m-p/763056#M11165</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enabled the app&amp;nbsp;SailPoint Identity Security Cloud AuditEvent but I'd like to ingest older event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no option in the configuration (I think) to set the time range on which the Splunk app gather events.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone faced the same issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2026 14:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/SailPoint-Get-older-events/m-p/763056#M11165</guid>
      <dc:creator>MandarinDefense</dc:creator>
      <dc:date>2026-08-21T14:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: [SailPoint] Get older events</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/SailPoint-Get-older-events/m-p/763062#M11166</link>
      <description>&lt;P&gt;The docs for the add-on - &lt;A href="https://community.sailpoint.com/t5/Identity-Security-Cloud-Wiki/SailPoint-Identity-Security-Cloud-AuditEvent-Add-on-for-Splunk/ta-p/77123#toc-hId--933693274" target="_blank"&gt;https://community.sailpoint.com/t5/Identity-Security-Cloud-Wiki/SailPoint-Identity-Security-Cloud-AuditEvent-Add-on-for-Splunk/ta-p/77123#toc-hId--933693274&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Say this:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; As of version 2.0.0, if the Splunk add-on loses its connection to Identity Security Cloud (manually disabled, credentials are removed, etc) for longer than a 24 hour period, it will begin collecting events from the time of reactivation/reconnection. For administrators, this means that if the add-on collection is suspended longer than 24 hours, audit events for this time period will not be available in Splunk. These events will still be retrievable via the IdentityNow API's.&lt;/P&gt;&lt;P&gt;I would read it as "the app reads at most 24 hours of backlog data". And it seems to be by design. You could fiddle with the add-on internals if it's in a readable form (I haven't checked if it's in python, as a binary or whatever).&lt;/P&gt;</description>
      <pubDate>Sat, 22 Aug 2026 11:01:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/SailPoint-Get-older-events/m-p/763062#M11166</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-08-22T11:01:56Z</dc:date>
    </item>
  </channel>
</rss>

