<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Aure China in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/650730#M79458</link>
    <description>&lt;P&gt;modify this one is error: &lt;SPAN&gt;self.cloud_environment = azure_cloud.CHINA_ACCOUNT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;the py file:&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;from&lt;/SPAN&gt; &lt;SPAN&gt;msrestazure&lt;/SPAN&gt; &lt;SPAN&gt;import&lt;/SPAN&gt; &lt;SPAN&gt;azure_cloud,&amp;nbsp; &amp;nbsp;s&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WeChat Image_20230717094716.png" style="width: 641px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26279i5EB638BA47B1AEA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="WeChat Image_20230717094716.png" alt="WeChat Image_20230717094716.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;so this is correct :&amp;nbsp;&lt;SPAN&gt;self.cloud_environment = azure_cloud.AZURE_CHINA_CLOUD&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;but still error:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;configuration inputs&amp;nbsp; such as azure resource&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;the log report &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WeChat Image_20230717095051.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26280iCF73063865830E1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="WeChat Image_20230717095051.png" alt="WeChat Image_20230717095051.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;the api link still use azure_public_cloud.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 17 Jul 2023 01:51:54 GMT</pubDate>
    <dc:creator>Jianming</dc:creator>
    <dc:date>2023-07-17T01:51:54Z</dc:date>
    <item>
      <title>Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Azure China?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/646898#M79280</link>
      <description>&lt;P&gt;Hi everyone:&lt;/P&gt;
&lt;P&gt;Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Aure China?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;Splunk Add-on for Azure&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;i create a new account. and create new input.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; but see the log report error&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;cat ta_ms_aad_azure_virtual_network.log&lt;BR /&gt;2023-06-14 10:32:07,118 INFO pid=4938 tid=MainThread file=setup_util.py:log_info:142 | Log level is not set, use default INFO&lt;BR /&gt;2023-06-14 10:32:07,118 INFO pid=4938 tid=MainThread file=setup_util.py:log_info:142 | Proxy is not enabled!&lt;BR /&gt;2023-06-14 10:32:08,558 ERROR pid=4938 tid=MainThread file=base_modinput.py:log_error:316 | Get error when collecting events.&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/lib/splunktaucclib/modinput_wrapper/base_modinput.py", line 140, in stream_events&lt;BR /&gt;self.collect_events(ew)&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/azure_virtual_network.py", line 212, in collect_events&lt;BR /&gt;raise RuntimeError("Unable to obtain access token. Please check the Client ID, Client Secret, and Tenant ID")&lt;BR /&gt;RuntimeError: Unable to obtain access token. Please check the Client ID, Client Secret, and Tenant ID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; Splunk Add-on for Microsoft Cloud Services&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;when i was created azure app account, report&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Account authentication failed. Please check your&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; credentials and try again&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Who know, the two add-on is support Azure China or not ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 16:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/646898#M79280</guid>
      <dc:creator>Jianming</dc:creator>
      <dc:date>2023-07-19T16:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Aure China</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/649013#M79377</link>
      <description>&lt;P&gt;To Pull China event Hub data, Splunk Add-on for Microsoft Cloud Services requires 2 changes:-&lt;BR /&gt;1st * Edit $SPLUNK_HOME/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunk_ta_mscs_rh_azureaccount.py&lt;BR /&gt;* Around line 88, we need to add a check for the Azure China region&lt;/P&gt;&lt;P&gt;if account_class_type == str(AccountClassType.GOVCLOUD_ACCOUNT):&lt;BR /&gt;self.cloud_environment = azure_cloud.AZURE_US_GOV_CLOUD&lt;BR /&gt;elif account_class_type == str(AccountClassType.CHINA_ACCOUNT):&lt;BR /&gt;self.cloud_environment = azure_cloud.CHINA_ACCOUNT&lt;BR /&gt;else:&lt;BR /&gt;self.cloud_environment = azure_cloud.AZURE_PUBLIC_CLOUD&lt;/P&gt;&lt;P&gt;2nd to map the event hubs $SPLUNK_HOME/etc/apps/Splunk_TA_microsoft-cloudservices/local&lt;BR /&gt;Create “mscs_azure_accounts.conf”&lt;/P&gt;&lt;P&gt;[ProvideName]&lt;BR /&gt;account_class_type = 3&lt;BR /&gt;client_id = ******&lt;BR /&gt;client_secret = ******&lt;BR /&gt;tenant_id = ******&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 13:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/649013#M79377</guid>
      <dc:creator>tarungupta0311</dc:creator>
      <dc:date>2023-07-03T13:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Aure China</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/650730#M79458</link>
      <description>&lt;P&gt;modify this one is error: &lt;SPAN&gt;self.cloud_environment = azure_cloud.CHINA_ACCOUNT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;the py file:&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;from&lt;/SPAN&gt; &lt;SPAN&gt;msrestazure&lt;/SPAN&gt; &lt;SPAN&gt;import&lt;/SPAN&gt; &lt;SPAN&gt;azure_cloud,&amp;nbsp; &amp;nbsp;s&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WeChat Image_20230717094716.png" style="width: 641px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26279i5EB638BA47B1AEA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="WeChat Image_20230717094716.png" alt="WeChat Image_20230717094716.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;so this is correct :&amp;nbsp;&lt;SPAN&gt;self.cloud_environment = azure_cloud.AZURE_CHINA_CLOUD&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;but still error:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;configuration inputs&amp;nbsp; such as azure resource&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;the log report &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WeChat Image_20230717095051.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26280iCF73063865830E1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="WeChat Image_20230717095051.png" alt="WeChat Image_20230717095051.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;the api link still use azure_public_cloud.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Jul 2023 01:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/650730#M79458</guid>
      <dc:creator>Jianming</dc:creator>
      <dc:date>2023-07-17T01:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Aure China</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/651066#M79474</link>
      <description>&lt;P&gt;I am also getting an Authentication error -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tarungupta0311_0-1689746402785.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26337iB37FC06C33120776/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tarungupta0311_0-1689746402785.png" alt="tarungupta0311_0-1689746402785.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 06:00:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/651066#M79474</guid>
      <dc:creator>tarungupta0311</dc:creator>
      <dc:date>2023-07-19T06:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Azure China?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697148#M80998</link>
      <description>&lt;P&gt;I have tried and failed. When asking for support, they replied no official support for Azure China. So this issue has not been resolved yet.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 14:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697148#M80998</guid>
      <dc:creator>DavidLi</dc:creator>
      <dc:date>2024-08-23T14:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Azure China?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697150#M81000</link>
      <description>&lt;P&gt;I have asked ChatGPT. The answer is as below. So I don't think there is easy way like modify conf file can reslove this issue.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;As of the latest available information, there are no widely recognized third-party solutions or community-contributed add-ons specifically tailored for Splunk to collect logs from Azure China. Most existing add-ons, including the official *Splunk Add-on for Microsoft Cloud Services*, are designed for the global Azure environment and may require customization to work with Azure China.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;### Options and Workarounds:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;1. **Customization of Existing Add-ons**:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#99CCFF"&gt;- You can manually modify the Splunk Add-on for Microsoft Cloud Services to point to the Azure China endpoints by editing the configuration files directly. This is the most common workaround but requires technical know-how to ensure compatibility and proper data collection.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;2. **Custom Scripts**:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#99CCFF"&gt;- If modifying existing add-ons is too complex or not feasible, you can create custom scripts using Azure SDKs (like Python SDK) to pull data from Azure China and forward it to Splunk using the HTTP Event Collector (HEC).&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;3. **Using REST API**:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#99CCFF"&gt;- Another approach is to use the Splunk Add-on for REST APIs to interact directly with Azure China's API endpoints. This method gives you the flexibility to collect any data available via the Azure China REST API.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;4. **Community Forums and Contributions**:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#99CCFF"&gt;- While specific tailored add-ons for Azure China are not available, you may find discussions or shared configurations on the [Splunk Community Forums](&lt;A href="https://community.splunk.com/" target="_blank"&gt;https://community.splunk.com/&lt;/A&gt;) or other community-driven platforms like GitHub, where users may have shared their custom solutions.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;### Keeping Up-to-Date:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#99CCFF"&gt;It's recommended to regularly check Splunkbase and participate in community discussions to stay updated on any new add-ons or tools that might become available for Azure China.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#99CCFF"&gt;For more details, you can visit [Splunkbase](&lt;A href="https://splunkbase.splunk.com/" target="_blank"&gt;https://splunkbase.splunk.com/&lt;/A&gt;) and the [Splunk Community](&lt;A href="https://community.splunk.com/)【" target="_blank"&gt;https://community.splunk.com/)【&lt;/A&gt;17†source】【18†source】.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 14:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697150#M81000</guid>
      <dc:creator>DavidLi</dc:creator>
      <dc:date>2024-08-23T14:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Azure China?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697804#M81028</link>
      <description>&lt;P&gt;Hi DavidLi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't realise that after a year you would still reply, thank you so much!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 07:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697804#M81028</guid>
      <dc:creator>Jianming</dc:creator>
      <dc:date>2024-08-30T07:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is the Splunk Add-on for Microsoft Cloud Services or Splunk Add-on for Azure Support collect Azure China?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697806#M81029</link>
      <description>&lt;P&gt;I have modified the api link of azure, and replaced all of them with the api url of azure China, but I can only collect a part of the data, not all of the data.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 07:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-the-Splunk-Add-on-for-Microsoft-Cloud-Services-or-Splunk-Add/m-p/697806#M81029</guid>
      <dc:creator>Jianming</dc:creator>
      <dc:date>2024-08-30T07:40:49Z</dc:date>
    </item>
  </channel>
</rss>

