Getting Data In

Microsoft Azure Add on for Splunk: backoff time not applied

phl92812
New Member

Hi,

when using the parameter query window size in the input to retrieve Azure AD signins the backoff time is not applied. 

For example, if the query limit is 10 minutes, and the checkpoint (the last event retrieved is from now - 5 minutes) then the query sent to the graph endpoint is between now() - 5 minutes and now() + 5 minutes.

Shouldn't the backoff time apply also when using a query limit? 

Thanks.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...