On the basis of the data I see from our tenant the add on is not retrieving all of the sign in records when compared with the Azure Portal sign in page.
The number of records loaded appears correlated with the polling frequency set. I have tried 300s (5m), 600s (10m) and 900s (15m). In each case the number of underlying events that the add on loads appears different. The effect is quite marked.
Query for the chart above:
index=liquid_it sourcetype="ms:aad:signin"
| timechart span=5m count
| eval tpm=round(count / 5, 2)
| fields - count
... View more