<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure Monitor - error message in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411111#M50162</link>
    <description>&lt;P&gt;The add-on is not required to run inside of Azure.  You can run it on Splunk 6.5+ anywhere an outbound connection can be made to Azure (on-prem, public cloud, private cloud).&lt;/P&gt;</description>
    <pubDate>Fri, 17 Aug 2018 23:01:24 GMT</pubDate>
    <dc:creator>jconger</dc:creator>
    <dc:date>2018-08-17T23:01:24Z</dc:date>
    <item>
      <title>Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411102#M50153</link>
      <description>&lt;P&gt;08-16-2018 16:31:19.869 -0500 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-Azure_Monitor/bin/azure_activity_log.sh" Modular input azure_activity_log://azure-event-hub-dev Error getting event hub creds: SyntaxError: Unexpected end of JSON input&lt;/P&gt;

&lt;P&gt;Does anyone know how to fix this?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411102#M50153</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2020-09-29T20:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411103#M50154</link>
      <description>&lt;P&gt;I don't like the Azure Monitor from MicroSoft or the Microsoft Cloud Services App from Splunk...&lt;/P&gt;

&lt;P&gt;Here is a method I developed for &lt;STRONG&gt;&lt;EM&gt;audit&lt;/EM&gt;&lt;/STRONG&gt; logs from Azure and O365 using the Log Analytics repositories.  &lt;/P&gt;

&lt;P&gt;This might work for you depending on what you are trying to get at: &lt;A href="https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html"&gt;https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, one of my co-workers whipped up a powershell script the other day to get at some data via the API that I couldn't get in Log Analytics and he just reused my http/HEC listener to post to.  &lt;/P&gt;

&lt;P&gt;I like the reliability and simplicity of this setup much better than some of the other options available.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 22:28:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411103#M50154</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2018-08-16T22:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411104#M50155</link>
      <description>&lt;P&gt;Can you post your inputs.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 22:48:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411104#M50155</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-08-16T22:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411105#M50156</link>
      <description>&lt;P&gt;I am not sure what you mean, the TA inputs are default.  I set it up through the GUI under data inputs activity_log.    Please explain which inputs I should look at.  Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 13:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411105#M50156</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2018-08-17T13:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411106#M50157</link>
      <description>&lt;P&gt;Thank you, we will look into this option.   Yes the azure apps have been a pain.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 13:06:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411106#M50157</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2018-08-17T13:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411107#M50158</link>
      <description>&lt;P&gt;So do you think your solution will work with an event hub in azure?  Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 13:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411107#M50158</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2018-08-17T13:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411108#M50159</link>
      <description>&lt;P&gt;probably...if theres some way to build a little logic app to query or receive from the event hub, but if the logs are something already available in Log Analytics and/or a "Solution"+Log Analytics you can do away with the event hub entirely&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 15:32:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411108#M50159</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2018-08-17T15:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411109#M50160</link>
      <description>&lt;P&gt;btw, this TA/App only works on Splunk Enterprise instances deployed inside Azure from the Azure Marketplace and it must be version 7+&lt;/P&gt;

&lt;P&gt;if you get it working you can then forward to wherever your main Splunk deployment is...&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 15:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411109#M50160</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2018-08-17T15:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411110#M50161</link>
      <description>&lt;P&gt;Can you share what you used for the values in the input (be sure to anonymize the values)?  This is what ends up in inputs.conf and will help troubleshoot.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 22:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411110#M50161</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-08-17T22:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411111#M50162</link>
      <description>&lt;P&gt;The add-on is not required to run inside of Azure.  You can run it on Splunk 6.5+ anywhere an outbound connection can be made to Azure (on-prem, public cloud, private cloud).&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 23:01:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411111#M50162</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-08-17T23:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Monitor - error message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411112#M50163</link>
      <description>&lt;P&gt;Thank you for the replies.&lt;BR /&gt;
Others have looked into this as well, and they have found a bug and abandoned the TA.&lt;BR /&gt;
I wanted to use the azure monitor with event hub to preclude manually entering accounts and inputs for all my azure data.&lt;/P&gt;

&lt;P&gt;Trying to automate the manual process with the API now.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 14:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Azure-Monitor-error-message/m-p/411112#M50163</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2018-09-05T14:32:21Z</dc:date>
    </item>
  </channel>
</rss>

