splunk / splunk-add-on-microsoft-azure

Splunk Add-on for Microsoft Azure
Apache License 2.0
11 stars 7 forks source link

Addon dropping events more than 50% #46

Closed Urus341 closed 3 months ago

Urus341 commented 1 year ago

Hello Guys, Observed that Addon is dropping events more than 50% in Log Analytics KQL. Is there any limitation that was configured in any script ?

The KQL query was running fine on Log analytics and giving the results but only few logs gets ingested into Splunk

Example: 10000 logs returned on Log analytics with KQL query. Only 5500 logs ingested into Splunk with same query configured on Add-on.

Would anyone please help here ?

JasonConger commented 3 months ago

KQL inputs have moved to the Splunk Add-on for Microsoft Cloud Services.