Splunk is getting duplicate events from Azure billing API, We are using inbuild azure connector to onboard the data.
2 Events are returned at the same time but the cost differs:
{"name": "subscriptionID ", "type": "Microsoft.Consumption/usageDetails", "tags": {"environment": "production", "application-name": ""}, "id": "/subscriptions/providers/Microsoft.Billing/billingPeriods/20200301/providers/Microsoft.Consumption/usageDetails/"properties