All Apps and Add-ons

what are the steps to configure Azure Diagnostics Splunk Add-on- Azure and splunk side?

Koko12345678
Explorer

I would like to know what are the specific steps and specific component I'll need to perform/create in order to configure/use Azure Diagnostics Splunk add-on. first from Azure side (e.g. VM with Azure Diagnostics extension ?storage account? Blob storage?), and then also from Splunk side.

I would appreciate if someone can provide a clear step by step to achieve this goal.

Thanks

Tags (1)
0 Karma

jconger
Splunk Employee
Splunk Employee

Diagnostic logs in Azure is a very broad topic. Almost all services in Azure can expose diagnostic logs in 1 of 2 ways:

  1. Send logs to an Azure Storage Account. The Splunk Add-on for Microsoft Cloud Services can read the logs written to the account.
  2. Send logs to an Event Hub. The Azure Monitor Add-on for Splunk can read logs from the Event Hub(s).

In either of the above cases, it involves creating a diagnostic setting in Azure first. The diagnostic setting controls where logs are sent (storage and/or Event Hub). If you send logs to storage, check out this blog on getting the data into Splunk. If you send logs to an Event Hub, refer to these blogs for Azure setup and Splunk setup.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...