Getting Data In

Certain Defender ATP alerts are being onboarded multiple times

RevatiLawrence
New Member

Hello,

I am trying to onboard Defender ATP alerts using Microsoft Defender ATP Add-on for Splunk (https://splunkbase.splunk.com/app/4959/but I can see certain alerts being onboarded multiple times. Has anyone else come across this type of issue before?

Thanks,

Revati

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...