All Apps and Add-ons

Splunk Add-on for Microsoft Azure: Where are connection log files stored?

SwiftSolves
New Member

I have a Splunk instance up and running and I have installed a Azure Connector to retrieve azure audit logs against Azure Government Cloud. I have modified AzureAudit.py on the Splunk server, but still getting a message "waiting for Data..." when searching against the data summary

Because the Splunk connector calls Azure Insights REST API, is their a way to read log files on these REST API calls to see what is failing? Do connectors in general store log files in /opt/splunk/var/log/splunk ? Or maybe a different directory or log file?

0 Karma

jconger
Splunk Employee
Splunk Employee

To get detailed information, set the logging level to DEBUG in the AzureAudit.py file (it is set to ERROR by default). Then, you can search the _internal index for detailed messages.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...