# Filebeat: Microsoft Module seems to be acquiring the same events for a period of time

**URL:** https://discuss.elastic.co/t/filebeat-microsoft-module-seems-to-be-acquiring-the-same-events-for-a-period-of-time/294179
**Category:** Beats
**Tags:** filebeat
**Created:** [January 12, 2022, 3:15pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-seems-to-be-acquiring-the-same-events-for-a-period-of-time/294179 "2022-01-12T15:15:05Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Log\_Gobbler](https://avatars.discourse-cdn.com/v4/letter/l/a183cd/32.png) [@Log\_Gobbler](https://discuss.elastic.co/u/Log_Gobbler)
#### Post date: [January 12, 2022, 3:15pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-seems-to-be-acquiring-the-same-events-for-a-period-of-time/294179/1 "2022-01-12T15:15:05Z")

</div>

I am testing the Filebeat Microsoft Module using the eicar test files from [Download Anti Malware Testfile – Eicar](https://www.eicar.org/?page_id=3950).  
I download one of the files. Then, Windows Defender AV "prevents" the infection (and generates events from Windows Defender AV). After waiting approximately 5 minutes, the intervals configured for the Microsoft module to pole for events, Kibana will have approximately 6 events per eicar test file that was downloaded/detected. Then, going forward, there will no longer be additional events associated with this activity. So it seems-like, to a degree (because it's not continuous), the Microsoft module is not aware of events it previously acquired. I have tested the polling interval using 2 minutes and 5 minutes. It does not seem to matter. We still get multiple events.

The Input URLs for the Microsoft Module are:

[https://api.securitycenter.windows.com/api/alerts](https://api.securitycenter.windows.com/api/alerts)  
[https://api.security.microsoft.com/api/incidents](https://api.security.microsoft.com/api/incidents)

Could someone please explain what could be going on here?

Below is the microsoft.yml for the Microsoft module:

```auto
# Module: microsoft
# Docs: https://www.elastic.co/guide/en/beats/filebeat/7.13/filebeat-module-microsoft.html

- module: microsoft
  # ATP configuration
  defender_atp:
    enabled: true
    # How often the API should be polled
    var.interval: 5m

    # Oauth Client ID
    var.oauth2.client.id: "Our Client ID"

    # Oauth Client Secret
# var.oauth2.client.secret: "Our Secret"
    var.oauth2.client.secret: "Our Secret"

    # Oauth Token URL, should include the tenant ID
    var.oauth2.token_url: "https://login.microsoftonline.com/16ed5ab4-2b59-4e40-806d-8a30bdc9cf26/oauth2/token"
  m365_defender:
    enabled: true
    # How often the API should be polled
    var.interval: 5m

    # Oauth Client ID
    var.oauth2.client.id: "Our Client ID"

    # Oauth Client Secret
# var.oauth2.client.secret: "Our Secret"
    var.oauth2.client.secret: "Our Secret"

    # Oauth Token URL, should include the tenant ID
    var.oauth2.token_url: "https://login.microsoftonline.com/16ed5ab4-2b59-4e40-806d-8a30bdc9cf26/oauth2/v2.0/token"
    
    # Related scopes, default should be included
    var.oauth2.scopes:
    - "https://api.security.microsoft.com/.default"
  dhcp:
    enabled: false

    # Set which input to use between udp (default), tcp or file.
    # var.input: udp
    # var.syslog_host: localhost
    # var.syslog_port: 9515

    # Set paths for the log files when file input is used.
    # var.paths:

    # Toggle output of non-ECS fields (default true).
    # var.rsa_fields: true

    # Set custom timezone offset.
    # "local" (default) for system timezone.
    # "+02:00" for GMT+02:00
    # var.tz_offset: local

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 9, 2022, 5:16pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-seems-to-be-acquiring-the-same-events-for-a-period-of-time/294179/2 "2022-02-09T17:16:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
