Getting Data In

Certain Defender ATP alerts are being onboarded multiple times

RevatiLawrence
New Member

Hello,

I am trying to onboard Defender ATP alerts using Microsoft Defender ATP Add-on for Splunk (https://splunkbase.splunk.com/app/4959/but I can see certain alerts being onboarded multiple times. Has anyone else come across this type of issue before?

Thanks,

Revati

Labels (1)
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!