<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what is the best way to use Splunk with Azure? Installing Universal fowarder on the VMs or use Splunk Add-on for Microsoft Cloud Services? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/what-is-the-best-way-to-use-Splunk-with-Azure-Installing/m-p/399016#M67768</link>
    <description>&lt;P&gt;A Universal Forwarder on an Azure VM gives you the most control of what you collect.  If your indexer is not in Azure, it could be a challenge as the receiving side of the UF will need to be accessible.&lt;/P&gt;

&lt;P&gt;If you just want performance data and Windows Event Logs from your VMS, I think it is easier to use the Splunk Add-on for Microsoft Cloud Services (MSCS).  Azure takes care of getting the data into a storage account.  The MSCS add-on pulls in this data.  Also, accessibility isn't as much of a concern here as the storage accounts are publicly accessible (with a key).&lt;/P&gt;

&lt;P&gt;The MSCS add-on has some more inputs that are useful including Audit, Resource, and generic storage.  So, a lot of people use a combination of UF and the MSCS add-on and the Azure Monitor add-on too.&lt;/P&gt;

&lt;P&gt;Regarding the question about changing your Splunk interface - the add-on is visible as a Splunk app for configuration.  No other changes are made.  The query method stays the same too.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jun 2018 22:15:05 GMT</pubDate>
    <dc:creator>jconger</dc:creator>
    <dc:date>2018-06-26T22:15:05Z</dc:date>
    <item>
      <title>what is the best way to use Splunk with Azure? Installing Universal fowarder on the VMs or use Splunk Add-on for Microsoft Cloud Services?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/what-is-the-best-way-to-use-Splunk-with-Azure-Installing/m-p/399015#M67767</link>
      <description>&lt;P&gt;I would like to know what are the benefits of using &lt;STRONG&gt;Splunk Add-on for Microsoft Cloud Services&lt;/STRONG&gt; over &lt;STRONG&gt;installing the Universal Forwarder directly on the VMs&lt;/STRONG&gt; ? do I'll get more/ better information by using Splunk Add-on for Microsoft Cloud Services? if yes, what is the differences?&lt;BR /&gt;&lt;BR /&gt;
In addition, if I'll choose to use Splunk Add-on for Microsoft Cloud Services, does my existing Splunk interface will be changed? does the query method will stay the same?  &lt;/P&gt;

&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 12:34:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/what-is-the-best-way-to-use-Splunk-with-Azure-Installing/m-p/399015#M67767</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-06-21T12:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: what is the best way to use Splunk with Azure? Installing Universal fowarder on the VMs or use Splunk Add-on for Microsoft Cloud Services?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/what-is-the-best-way-to-use-Splunk-with-Azure-Installing/m-p/399016#M67768</link>
      <description>&lt;P&gt;A Universal Forwarder on an Azure VM gives you the most control of what you collect.  If your indexer is not in Azure, it could be a challenge as the receiving side of the UF will need to be accessible.&lt;/P&gt;

&lt;P&gt;If you just want performance data and Windows Event Logs from your VMS, I think it is easier to use the Splunk Add-on for Microsoft Cloud Services (MSCS).  Azure takes care of getting the data into a storage account.  The MSCS add-on pulls in this data.  Also, accessibility isn't as much of a concern here as the storage accounts are publicly accessible (with a key).&lt;/P&gt;

&lt;P&gt;The MSCS add-on has some more inputs that are useful including Audit, Resource, and generic storage.  So, a lot of people use a combination of UF and the MSCS add-on and the Azure Monitor add-on too.&lt;/P&gt;

&lt;P&gt;Regarding the question about changing your Splunk interface - the add-on is visible as a Splunk app for configuration.  No other changes are made.  The query method stays the same too.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 22:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/what-is-the-best-way-to-use-Splunk-with-Azure-Installing/m-p/399016#M67768</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-06-26T22:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: what is the best way to use Splunk with Azure? Installing Universal fowarder on the VMs or use Splunk Add-on for Microsoft Cloud Services?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/what-is-the-best-way-to-use-Splunk-with-Azure-Installing/m-p/399017#M67769</link>
      <description>&lt;P&gt;Thank you for your response, appreciate your help!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 07:56:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/what-is-the-best-way-to-use-Splunk-with-Azure-Installing/m-p/399017#M67769</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-06-27T07:56:05Z</dc:date>
    </item>
  </channel>
</rss>

