Preventing Log Loss Caused by Delayed Events in the Events API
We use the Box Events API to send event logs to Sumo Logic.
We are currently experiencing recurring cases where events that appear in the User Activity Report in the Box Admin Console are not present in the Box event logs collected by Sumo Logic.
We asked Sumo Logic to investigate this issue. They explained that the Box Source continuously retrieves events using the position information returned by the Events API. However, there may be a delay between the time an action occurs in Box and the time the corresponding event becomes available through the API. If a delayed event is later added to a range that has already been processed, it may no longer be retrieved.
We have observed this behavior in our environment, where some events appear in the User Activity Report but cannot be found in Sumo Logic.
Because we send these event logs to Sumo Logic for auditing and security purposes, we would appreciate an enhancement that ensures delayed events can also be retrieved without being missed.
Please consider improving the Events API so that events can be retrieved reliably during continuous log collection.
【In Japanese】
<タイトル>
Events APIにおける遅延イベントログの欠落防止について
<本文>
BoxのEvents APIを利用して、Sumo Logicへイベントログを連携しています。
現在、Box Admin ConsoleのUser Activity Reportでは確認できるイベントが、Sumo Logicで収集したBoxイベントログには存在しないケースが継続して発生しています。
Sumo Logicへ調査を依頼したところ、Box SourceではEvents APIから返却される位置情報を利用して継続的にイベントを取得している一方、Box上での操作時刻とイベントがAPIから取得可能になる時刻に差が生じる場合があり、遅れて公開されたイベントがすでに取得済みの範囲に追加された場合、取得できなくなる可能性があるとの説明を受けています。
実際に当環境でも、User Activity Report上には存在するものの、Sumo Logicでは確認できないイベントが発生しています。
監査・セキュリティ用途でイベントログをSumo Logicへ連携しているため、遅延して公開されたイベントについても欠落なく取得できる仕組みをご検討いただけないでしょうか。
Events APIを利用した継続的なログ収集において、イベントを確実に取得できるよう改善をお願いいたします。