# Error "Event created before query" using o365 module

**URL:** <https://discuss.elastic.co/t/error-event-created-before-query-using-o365-module/323759>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 23, 2023, 7:28pm UTC](https://discuss.elastic.co/t/error-event-created-before-query-using-o365-module/323759 "2023-01-23T19:28:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Apaquette](https://avatars.discourse-cdn.com/v4/letter/a/f475e1/32.png) [@Apaquette](https://discuss.elastic.co/u/Apaquette)\
**Post date:** [January 23, 2023, 7:28pm UTC](https://discuss.elastic.co/t/error-event-created-before-query-using-o365-module/323759/1 "2023-01-23T19:28:36Z")

</div>

Hello,

We use Filebeat's module for Office 365 to gather audit logs and send them to our SIEM.

We detected multiple errors in the module's logs. We can read "Event created before query" (with a little bit more information around). We need to understand the impact of this error (lost logs, logs in double, etc.).

We are wondering if anybody got this error also and if so, what is this error and what can be done to resolve it.

Here is the link to the module we use:

> **[Office 365 module | Filebeat Reference \[8.6\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-o365.html)**

The filebeat version used is 7.13.4

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2023, 9:29pm UTC](https://discuss.elastic.co/t/error-event-created-before-query-using-o365-module/323759/2 "2023-02-20T21:29:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
