Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.37k stars 2.89k forks source link

Cisco Meraki Events via REST API overutilization and data duplication #10675

Open shaunyb93 opened 2 weeks ago

shaunyb93 commented 2 weeks ago

Hi team I understand that this connector is in preview but we are facing an issue and would like to report it.

We are seeing the getOrganizationConfigurationChanges running ~21000 times per hour This is resulting in excess data being logged in ASimWebSessionLogs table

We are also seeing changes from are being retrieved by the connector using the getOrganizationConfigurationChanges function are duplicated thousands of times in the ASimAuditEventLogs table.

Please can we get some help with this - I will likely need to disconnect the connector.

Thank you

v-rusraut commented 1 week ago

Hi @shaunyb93, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 26 June 2024. Thanks!