data connector issue Microsoft sentinel

Nimantha Deshappriya 21 Reputation points
2022-10-18T05:12:32.507+00:00

Checkpoint data connector was recently connected to Microsoft Sentinel.

I have now realized the duplicate events are coming from both syslog table and commonsecurity table.

251451-1.png

I want to stop syslogs event coming to sentinel and let it ingest via commonsecurity logs.

This above issue has resulted in high ingestion cost. Appreciate if you can share a prompt solution

Microsoft Security Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. Clive Watson 7,866 Reputation points MVP Volunteer Moderator
    2022-10-18T08:31:40.767+00:00

    Please see this (the screenshot) https://techcommunity.microsoft.com/t5/microsoft-sentinel/urgent-cef-syslog-duplication-issue/m-p/2474682

    I hope this answers your question, if so please Accept

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.