Getting Data In

O365 Duplicate events

mailmetoramu
Explorer

Hello All,

I m getting duplicate events for my O365 logs.Have checked from my O365 side configurations and seems everything fine from O365 end.

Is this something need to corrected from Splunk side ??

Thanks,

Ramu.R

Tags (1)

marycordova
SplunkTrust
SplunkTrust

A possible better way of getting logs from O365/Azure: https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html

@marycordova
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@mailmetoramu

I think you are facing Issue registered as known issue: ADDON-20076. Can you please check & confirm it? Or it something new.

https://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...