Getting Data In

Moving files from Azure Blob Storage to Splunk Cloud

osmar_countdown
New Member

Hi,

Are there any plugins or up to date tutorials on how to move files from Azure blob storage to Splunk Cloud? Are there any best practices recommended on how to approach the forwarding from Azure to Splunk Cloud?

I have seen the HTTP Collector and I believe it could possibly be a solution in conjunction with Event Hubs and/or Azure Functions, but I'm not sure if that would be correct and the most recommended.

Any examples would be much appreciated.

Kind regards,
Osmar

Tags (3)
0 Karma

jconger
Splunk Employee
Splunk Employee

You can use a heavy forwarder with the Splunk Add-on for Microsoft Cloud Services to read data from the blob and forward on to Splunk Cloud. This heavy forwarder could live in Azure, on your premises, or anywhere that has access to the internet. With Splunk Cloud, you could get an Input Data Manager (IDM) provisioned that could run the add-on as well.

Anything specific you are looking to get from the Azure blob? Is it diagnostic data/logs from other Azure resources? If so, there may be a better/easier way to do it versus using blobs.

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...