All Apps and Add-ons

what are the steps to configure Azure Diagnostics Splunk Add-on- Azure and splunk side?

Koko12345678
Explorer

I would like to know what are the specific steps and specific component I'll need to perform/create in order to configure/use Azure Diagnostics Splunk add-on. first from Azure side (e.g. VM with Azure Diagnostics extension ?storage account? Blob storage?), and then also from Splunk side.

I would appreciate if someone can provide a clear step by step to achieve this goal.

Thanks

Tags (1)
0 Karma

jconger
Splunk Employee
Splunk Employee

Diagnostic logs in Azure is a very broad topic. Almost all services in Azure can expose diagnostic logs in 1 of 2 ways:

  1. Send logs to an Azure Storage Account. The Splunk Add-on for Microsoft Cloud Services can read the logs written to the account.
  2. Send logs to an Event Hub. The Azure Monitor Add-on for Splunk can read logs from the Event Hub(s).

In either of the above cases, it involves creating a diagnostic setting in Azure first. The diagnostic setting controls where logs are sent (storage and/or Event Hub). If you send logs to storage, check out this blog on getting the data into Splunk. If you send logs to an Event Hub, refer to these blogs for Azure setup and Splunk setup.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...