First of all, thank you for the app. The setup, import, and event classification is great.
The issue I am having is that authentication events with a reason of "Allow unenrolled user" are not included in the import. I couldn't see anything in the python or within the app to restrict/filter events. Any ideas?
You are correct, the add-on doesn't do any filtering of events. It simply pulls the raw logs from DUO in their default json format and indexes them. There is some eventyping done for CIM compliance, but that doesn't change the indexed data.
If you have access, or someone else in your org has access to DUO's admin web interface, do you see those events listed there? If so, I'd be interested in knowing that, I haven't heard of any issues like this. I've had the add-on published for a couple of years and it hasn't changed much, but that doesn't mean something hasn't changed on DUO's side. DUO publishes their own Splunk app as well now, so I've been debating whether I should update mine or not.