All Apps and Add-ons

UserID in Microsoft 365 App for Splunk

jgeorges
Engager

I'm new to Splunk and the the Microsoft 365 App.   On many of the screens it will show logs and include only the raw "UserID" (eg. 7eaa8557-21cc-4242-baba-123456789abc) which makes visual identification difficult.

I just want to confirm that this is the expected behaviour, and is there an easy way to include the UserKey in addition/instead ?  Or is it a matter of setting up my own dashboards from a duplicate ?

Appreciate any thoughts.

J

 

Labels (1)
0 Karma

USAFA
New Member

We have been seeing this lately as well.  Oddly the field "UserKey" will have the information that you are looking for.  I am not sure when or if the app will be updated.  

0 Karma

jgeorges
Engager

Thanks USAFA,

So it sounds like it is something that has changed recently ?  At least it isn't just my installation then I guess.

0 Karma

moogmusic
Path Finder

We're seeing this as well - looks like it changed on or around October 29th. Not sure whether to wait for an update in the Splunk Add-on for Microsoft Office 365 or just manually fix the Data Model?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...