Hello,
We have logstash performing dual feed. The first output writes to Elastic and the second output writes to Azure Sentinel.
There is a clear delta in number of logs sent to Azure Sentinel and Elastic. Elastic receives all the events, and there is a drop on Azure Sentinel.
In terms of troubleshooting, can you please advise on how can I hunt for the drops.
Thanks in advance.
--
Regards,
Siddarth