All Apps and Add-ons

What is the reason for Splunk_TA_microsoft-cloudservices missing data?

rayar
Contributor

we have integration with EventHub using Splunk_TA_microsoft-cloudservices

we see that events are missing 

what might be the reason  ? 

in case the event reached the EventHub with delay , will the APP pull the data  ?

how much time back the APP is scanning the data  ?

Labels (1)
0 Karma

shivanshu1593
Builder

Needs a lot of more context from your side but generally speaking the add-on makes a checkpoint based off an offset value that is present in the data, which helps it to recognize as to what it pulled the last time and start ingesting the next log to avoid duplication. Which also answers your other question, how far is the add-on scanning the data.

To identify your issue, a lot more context about the integration would be needed but since you are using Splunk_TA_microsoft-cloudservices, I'd recommend opening a support case with Splunk and submitting a diag file of the server where the add-on is hosted and working. They will be able to help you out.

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...