Skip to main content

Office365 Feed API is creating duplicate entries in Chronicle

  • August 8, 2024
  • 1 reply
  • 22 views

Forum|alt.badge.img+5

Hi Team,

We are utilizing Chronicle Feed to ingest Office 365 logs. We have integrated Audit.AzureActiveDirectory, Audit.Exchange, Audit.SharePoint, Audit.General, and DLP.All as the sources. We are seeing duplicate entries of the authentication logs. This was verified as logs with same raw log (all characters) and same value in metadata.product_log_id is repeated  2-3 times on average (up to 16 times) increasing false positives and data misrepresentation on the dashboard. 

Has someone discovered this issue and if yes is there any solution to this?

1 reply

dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • August 8, 2024

Hello, 

Assuming this is configured as a feed?  From time to we do get duplicates and need to adjust timings.  Please open a support case with the feed ID’s in question and they will prioritize as a bug fix.