Hi,
what is LogPoint's recommended way to get logs from Azure AD / EntraID and any other Azure applications into LogPoint?
We have noticed that the Azure EventHubs sometimes provide their logs several days late via the message queue. We were able to verify this independently of LogPoint using a fetcher developed in Python.
How does this work with the "Azure Log Analytics Workspace" module? Can the logs be expected in the SIEM in a timely manner?
A delay of several hours and days is not possible with the current alert rule concept of searching on already indexed timeranges without running the alert rules on utopian high timeranges.