All Apps and Add-ons

How is how_time set when experiencing TA-MS-AAD data indexing delays?

rayar
Contributor

I have configuration  for TA-MS-AAD and we see that we have delays 

trying to understand how _time is set 

Labels (1)
0 Karma

davidoff96
Path Finder

If I understand this correctly, this is for this add-on: https://splunkbase.splunk.com/app/3757

 

Which sourcetype are you seeing _time issues with? Each sourcetype has a different method of getting _time (some use "createdDateTime", others use CURRENT).

0 Karma

rayar
Contributor
02:05:192023-01-22 08:13:192023-01-22 06:08:00.000azure:eventhub
02:05:412023-01-22 08:08:412023-01-22 06:03:00.000azure:eventhub
02:05:412023-01-22 08:08:412023-01-22 06:03:00.000azure:eventhub
02:05:512023-01-22 08:08:512023-01-22 06:03:00.000azure:eventhub
02:05:512023-01-22 08:08:512023-01-22 06:03:00.000azure:eventhub
02:06:092023-01-22 08:09:092023-01-22 06:03:00.000azure:eventhub
02:06:092023-01-22 08:09:092023-01-22 06:03:00.000azure:eventhub
02:06:392023-01-22 08:20:392023-01-22 06:14:00.000azure:eventhub
02:07:082023-01-22 08:13:082023-01-22 06:06:00.000azure:eventhub
    
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...