Logs for CurrentStatus endpoint show events which have a 24 hour old timestamp. Is this a bug in the add-on? or does Microsoft Current Status Logs from API can only give you details for 24hours old data.
Indextime shows current datettime - 2018-12-11 12:45:19.207
But the actual _time on the event shows 2018-12-11 12:45:19.207
This is not a splunk bug. The CurrentStatus response will contain the status and any incidents within the previous 24 hours. The StatusDate or StatusTime value returned will be exactly 24 hours in the past. So Current Status is acctually yesterdays Status.
This does not really answer the OPs question as CurrentStatus is not a function of auditing users. It is the status of the service we are having the same issue and trying to determine why it is 24 hours behind when Epoch time it is requesting is current