<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data Parsing Issue - Ingesting The Logs Using Splunk Add-On For Microsoft Cloud Services in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707576#M81346</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We initially received a requirement to configure and ingest logs from Azure Storage Blob. To address this, we installed the Splunk Add-On for Microsoft Cloud Services on our Heavy Forwarder servers and configured it to pull logs from Azure Storage Blob using the Azure Storage Account.&lt;/P&gt;&lt;P&gt;Currently, there's a new requirement to ingest Databricks logs from Azure Storage Blob. We completed the necessary configurations and set the default sourcetype to mscs:storage:blob for data parsing. While the events are visible in Splunk after the configuration, we noticed that the data parsing is not functioning as expected for these events.&lt;/P&gt;&lt;P&gt;As a troubleshooting step, I changed the sourcetype to mscs:storage:blob:json, but the issue still persists.&lt;/P&gt;&lt;P&gt;Could you please assist me in resolving this issue? Your guidance would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Dec 2024 13:07:55 GMT</pubDate>
    <dc:creator>anandhalagaras1</dc:creator>
    <dc:date>2024-12-26T13:07:55Z</dc:date>
    <item>
      <title>Data Parsing Issue - Ingesting The Logs Using Splunk Add-On For Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707576#M81346</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We initially received a requirement to configure and ingest logs from Azure Storage Blob. To address this, we installed the Splunk Add-On for Microsoft Cloud Services on our Heavy Forwarder servers and configured it to pull logs from Azure Storage Blob using the Azure Storage Account.&lt;/P&gt;&lt;P&gt;Currently, there's a new requirement to ingest Databricks logs from Azure Storage Blob. We completed the necessary configurations and set the default sourcetype to mscs:storage:blob for data parsing. While the events are visible in Splunk after the configuration, we noticed that the data parsing is not functioning as expected for these events.&lt;/P&gt;&lt;P&gt;As a troubleshooting step, I changed the sourcetype to mscs:storage:blob:json, but the issue still persists.&lt;/P&gt;&lt;P&gt;Could you please assist me in resolving this issue? Your guidance would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2024 13:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707576#M81346</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-12-26T13:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Data Parsing Issue - Ingesting The Logs Using Splunk Add-On For Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707857#M81353</link>
      <description>&lt;P&gt;Can anyone help on my request.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 08:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707857#M81353</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2025-01-02T08:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Data Parsing Issue - Ingesting The Logs Using Splunk Add-On For Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707868#M81354</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you checked this community page?&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Cloud-Services-How-to-edit-props/m-p/242367" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Cloud-Services-How-to-edit-props/m-p/242367&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 10:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707868#M81354</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-01-02T10:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Data Parsing Issue - Ingesting The Logs Using Splunk Add-On For Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707877#M81355</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have tried the same as per the community page but still its the same the data are not getting parsed.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 11:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/707877#M81355</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2025-01-02T11:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Data Parsing Issue - Ingesting The Logs Using Splunk Add-On For Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/708043#M81363</link>
      <description>&lt;P&gt;Could you please share the sample raw logs and how are those looking in Splunk once they are ingested? Issues with Line breaking, timestamp assignment, field extraction?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 13:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-Parsing-Issue-Ingesting-The-Logs-Using-Splunk-Add-On-For/m-p/708043#M81363</guid>
      <dc:creator>rishabhshah</dc:creator>
      <dc:date>2025-01-06T13:41:58Z</dc:date>
    </item>
  </channel>
</rss>

