<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure Firewall Logs Issue in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/703787#M20728</link>
    <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;&lt;P&gt;I’ve set up Azure Firewall logging, selecting all firewall logs and archiving them to a storage account (Event Hub was avoided due to cost concerns). The configuration steps taken are as follows:&lt;/P&gt;&lt;P&gt;Log Archival:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All Azure Firewall logs are set to archive in a storage account&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Microsoft Cloud Add-On&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I added the storage account to the Microsoft Cloud Add-On using the secret key with the following permissions:&lt;/LI&gt;&lt;/UL&gt;&lt;TABLE width="1133"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="219"&gt;Input/Action&lt;/TD&gt;&lt;TD width="178"&gt;API&lt;/TD&gt;&lt;TD width="316"&gt;Permissions&lt;/TD&gt;&lt;TD width="136"&gt;Role (IAM)&lt;/TD&gt;&lt;TD width="284"&gt;Default Sourcetype(s) / Sources&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="219"&gt;Azure Storage Table&lt;BR /&gt;Azure Storage Blob&lt;/TD&gt;&lt;TD width="178"&gt;N/A&lt;/TD&gt;&lt;TD width="316"&gt;Access key&amp;nbsp; OR&lt;BR /&gt;Shared Access Signature:&lt;BR /&gt;&amp;nbsp; - Allowed services: Blob, Table&lt;BR /&gt;&amp;nbsp; - Allowed resource types: Service, Container, Object&lt;BR /&gt;&amp;nbsp; - Allowed permissions: Read, List&lt;/TD&gt;&lt;TD width="136"&gt;N/A&lt;/TD&gt;&lt;TD width="284"&gt;mscs:storage:blob &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; (Received this)&lt;BR /&gt;mscs:storage:blob:json &lt;span class="lia-unicode-emoji" title=":cross_mark:"&gt;❌&lt;/span&gt;&lt;BR /&gt;mscs:storage:blob:xml&lt;span class="lia-unicode-emoji" title=":cross_mark:"&gt;❌&lt;/span&gt;&lt;BR /&gt;mscs:storage:table&lt;span class="lia-unicode-emoji" title=":cross_mark:"&gt;❌&lt;/span&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;We are receiving events from the source files in JSON format, but there are two issues:&lt;/P&gt;&lt;P&gt;Field Extraction:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Critical fields such as protocol, action, source, destination, etc., are not being identified.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Incomplete Logs:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Logs appear truncated, starting with partial data (e.g., “urceID:…”) and missing “Reso,” which implies dropped or incomplete events (As far as I understand)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Few logs were received compared to the traffic on Azure Firewall. Attached is a piece of logs showing errors as mentioned in the question.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Azure Firewall.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33405iDD77E3D1CE2C3FD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Azure Firewall.png" alt="Azure Firewall.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;________________________________________________________________&lt;/P&gt;&lt;P&gt;Environment Details:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;•	Log Collector: Heavy Forwarder (HF) hosted in Azure.
•	Data Flow: Logs are being forwarded to Splunk Cloud&amp;nbsp;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Can it be an issue with using storage accounts and not event-hub?&lt;/LI&gt;&lt;LI&gt;Could the incomplete logs be due to a configuration issue with the Microsoft Cloud Add-On or possibly related to the data transfer between the storage account and Splunk?&lt;/LI&gt;&lt;LI&gt;Has anyone encountered similar issues with field extraction from Azure Firewall JSON logs?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Ultimate Goal:&lt;/P&gt;&lt;P&gt;Receive Azure Firewall Logs with fields extracted as any other firewall logs received by Syslog (Fortinet for example)&lt;/P&gt;&lt;P&gt;Any guidance or troubleshooting suggestions would be much appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2024 10:03:54 GMT</pubDate>
    <dc:creator>MeWoW</dc:creator>
    <dc:date>2024-11-07T10:03:54Z</dc:date>
    <item>
      <title>Azure Firewall Logs Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/703787#M20728</link>
      <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;&lt;P&gt;I’ve set up Azure Firewall logging, selecting all firewall logs and archiving them to a storage account (Event Hub was avoided due to cost concerns). The configuration steps taken are as follows:&lt;/P&gt;&lt;P&gt;Log Archival:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All Azure Firewall logs are set to archive in a storage account&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Microsoft Cloud Add-On&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I added the storage account to the Microsoft Cloud Add-On using the secret key with the following permissions:&lt;/LI&gt;&lt;/UL&gt;&lt;TABLE width="1133"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="219"&gt;Input/Action&lt;/TD&gt;&lt;TD width="178"&gt;API&lt;/TD&gt;&lt;TD width="316"&gt;Permissions&lt;/TD&gt;&lt;TD width="136"&gt;Role (IAM)&lt;/TD&gt;&lt;TD width="284"&gt;Default Sourcetype(s) / Sources&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="219"&gt;Azure Storage Table&lt;BR /&gt;Azure Storage Blob&lt;/TD&gt;&lt;TD width="178"&gt;N/A&lt;/TD&gt;&lt;TD width="316"&gt;Access key&amp;nbsp; OR&lt;BR /&gt;Shared Access Signature:&lt;BR /&gt;&amp;nbsp; - Allowed services: Blob, Table&lt;BR /&gt;&amp;nbsp; - Allowed resource types: Service, Container, Object&lt;BR /&gt;&amp;nbsp; - Allowed permissions: Read, List&lt;/TD&gt;&lt;TD width="136"&gt;N/A&lt;/TD&gt;&lt;TD width="284"&gt;mscs:storage:blob &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; (Received this)&lt;BR /&gt;mscs:storage:blob:json &lt;span class="lia-unicode-emoji" title=":cross_mark:"&gt;❌&lt;/span&gt;&lt;BR /&gt;mscs:storage:blob:xml&lt;span class="lia-unicode-emoji" title=":cross_mark:"&gt;❌&lt;/span&gt;&lt;BR /&gt;mscs:storage:table&lt;span class="lia-unicode-emoji" title=":cross_mark:"&gt;❌&lt;/span&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;We are receiving events from the source files in JSON format, but there are two issues:&lt;/P&gt;&lt;P&gt;Field Extraction:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Critical fields such as protocol, action, source, destination, etc., are not being identified.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Incomplete Logs:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Logs appear truncated, starting with partial data (e.g., “urceID:…”) and missing “Reso,” which implies dropped or incomplete events (As far as I understand)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Few logs were received compared to the traffic on Azure Firewall. Attached is a piece of logs showing errors as mentioned in the question.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Azure Firewall.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33405iDD77E3D1CE2C3FD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Azure Firewall.png" alt="Azure Firewall.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;________________________________________________________________&lt;/P&gt;&lt;P&gt;Environment Details:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;•	Log Collector: Heavy Forwarder (HF) hosted in Azure.
•	Data Flow: Logs are being forwarded to Splunk Cloud&amp;nbsp;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Can it be an issue with using storage accounts and not event-hub?&lt;/LI&gt;&lt;LI&gt;Could the incomplete logs be due to a configuration issue with the Microsoft Cloud Add-On or possibly related to the data transfer between the storage account and Splunk?&lt;/LI&gt;&lt;LI&gt;Has anyone encountered similar issues with field extraction from Azure Firewall JSON logs?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Ultimate Goal:&lt;/P&gt;&lt;P&gt;Receive Azure Firewall Logs with fields extracted as any other firewall logs received by Syslog (Fortinet for example)&lt;/P&gt;&lt;P&gt;Any guidance or troubleshooting suggestions would be much appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 10:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/703787#M20728</guid>
      <dc:creator>MeWoW</dc:creator>
      <dc:date>2024-11-07T10:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Firewall Logs Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706814#M21089</link>
      <description>&lt;P&gt;Splunk Support Update:&lt;BR /&gt;Regarding your question about the best way to ingest Azure Firewall logs into Splunk, I would recommend using Event Hub for this purpose. Event Hub allows you to stream real-time data, which is ideal for continuous log ingestion. On the other hand, using Storage Blob as an input can lead to delays, especially as log sizes increase, and could also result in data duplication.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2024 10:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706814#M21089</guid>
      <dc:creator>MeWoW</dc:creator>
      <dc:date>2024-12-15T10:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Firewall Logs Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706824#M21090</link>
      <description>&lt;P&gt;As usual, there might probably be more than one solution to a problem (in your case - ingestion of Azure Firewall logs). True, Event Hub will give you a near-realtime (it's not strictly realtime since it's pull-based as far as I remember) but the storage-based method might be cheaper and if you're ok with the latency it might be sufficient.&lt;/P&gt;&lt;P&gt;Your original problems were most probably caused by misconfigured sourcetype. The input data was not broken into events properly and/or the events were to long and got truncated.&lt;/P&gt;&lt;P&gt;As a result json extractions didn't happen because the events were not well-formed jsons.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2024 20:24:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706824#M21090</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-15T20:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Firewall Logs Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706911#M21102</link>
      <description>&lt;P&gt;Thank you for your input. Might be the line breaker field that is causing this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition, the amount of events received is low taking into consideration it's an Azure Firewall with 10-15 GB Daily of logs.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 15:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706911#M21102</guid>
      <dc:creator>MeWoW</dc:creator>
      <dc:date>2024-12-16T15:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Firewall Logs Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706913#M21103</link>
      <description>&lt;P&gt;That's to be expected as well. If your input is not broken into single events properly you might end up with a small number of huge data blobs (effectively consisting of several "atomic" events). Since they'd get cut off at TRUNCATE point, all the data following that point would be lost.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 15:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Azure-Firewall-Logs-Issue/m-p/706913#M21103</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-16T15:03:43Z</dc:date>
    </item>
  </channel>
</rss>

