Missing indicators from Graph Security API submission

SentinelNoob 191 Reputation points
2021-01-10T09:04:49.537+00:00

Hi Community,

Using the Graph Security API, I submitted 1.9 million unique network ip indicators to my Sentinel workspace with concurrent threads. I verified the count via responses from the API. However, the sentinel only shows the ingestion of roughly 1.2 million unique indicators after much delay.

What happen to the rest? Did api drop them somehow? If it did, wouldn't the response tell me so?
Is there a limit on ingestion that I've not noticed?

Much appreciate any help!

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Deva-MSFT 2,256 Reputation points Microsoft Employee
    2021-01-12T18:27:16.3+00:00

    As you're getting good amount of data, i am not sure you tried the pagination (check the constraints section & workaround) ?

    0 comments No comments