All Apps and Add-ons

UserID in Microsoft 365 App for Splunk

jgeorges
Engager

I'm new to Splunk and the the Microsoft 365 App.   On many of the screens it will show logs and include only the raw "UserID" (eg. 7eaa8557-21cc-4242-baba-123456789abc) which makes visual identification difficult.

I just want to confirm that this is the expected behaviour, and is there an easy way to include the UserKey in addition/instead ?  Or is it a matter of setting up my own dashboards from a duplicate ?

Appreciate any thoughts.

J

 

Labels (1)
0 Karma

USAFA
New Member

We have been seeing this lately as well.  Oddly the field "UserKey" will have the information that you are looking for.  I am not sure when or if the app will be updated.  

0 Karma

jgeorges
Engager

Thanks USAFA,

So it sounds like it is something that has changed recently ?  At least it isn't just my installation then I guess.

0 Karma

moogmusic
Path Finder

We're seeing this as well - looks like it changed on or around October 29th. Not sure whether to wait for an update in the Splunk Add-on for Microsoft Office 365 or just manually fix the Data Model?

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...