We recently configured and setup an integration with webex logs coming into Splunk. We can confirm those logs are now coming in, but we have noticed some unusual behavior with the various sourcetype logs associated with the webex history service, which give us the meaningful events/fields needed to build alerts and dashboards. the data coming in is 2-5 days older. The splunk input is configured to use an API call to pull data across at a maximum of every 24 hour period (most regular setting available) so would expect the data to be at least a day old at the maximum.We use the Splunk plugin which make API calls to retrieve the data from webex and send to Splunk.Plugin provides options to retrieve data for active scheduled sessions or historical meetings.
We checked classical reports in webex admin portals and found they shows the most recent data. can we make use of are preliminary history APIs that classic reports using to get the most recent data.Plugin information can be found at