All Apps and Add-ons

UserID in Microsoft 365 App for Splunk

jgeorges
Engager

I'm new to Splunk and the the Microsoft 365 App.   On many of the screens it will show logs and include only the raw "UserID" (eg. 7eaa8557-21cc-4242-baba-123456789abc) which makes visual identification difficult.

I just want to confirm that this is the expected behaviour, and is there an easy way to include the UserKey in addition/instead ?  Or is it a matter of setting up my own dashboards from a duplicate ?

Appreciate any thoughts.

J

 

Labels (1)
0 Karma

USAFA
New Member

We have been seeing this lately as well.  Oddly the field "UserKey" will have the information that you are looking for.  I am not sure when or if the app will be updated.  

0 Karma

jgeorges
Engager

Thanks USAFA,

So it sounds like it is something that has changed recently ?  At least it isn't just my installation then I guess.

0 Karma

moogmusic
Path Finder

We're seeing this as well - looks like it changed on or around October 29th. Not sure whether to wait for an update in the Splunk Add-on for Microsoft Office 365 or just manually fix the Data Model?

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...