All Apps and Add-ons

Splunk Add-on for Microsoft Azure: Where are connection log files stored?

SwiftSolves
New Member

I have a Splunk instance up and running and I have installed a Azure Connector to retrieve azure audit logs against Azure Government Cloud. I have modified AzureAudit.py on the Splunk server, but still getting a message "waiting for Data..." when searching against the data summary

Because the Splunk connector calls Azure Insights REST API, is their a way to read log files on these REST API calls to see what is failing? Do connectors in general store log files in /opt/splunk/var/log/splunk ? Or maybe a different directory or log file?

0 Karma

jconger
Splunk Employee
Splunk Employee

To get detailed information, set the logging level to DEBUG in the AzureAudit.py file (it is set to ERROR by default). Then, you can search the _internal index for detailed messages.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...