<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A splunk command to query Azure Monitor in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/A-splunk-command-to-query-Azure-Monitor/m-p/756396#M12074</link>
    <description>&lt;P&gt;Azure Monitor collects metrics and logs across many different resource types. For example, if you want to view CPU and memory metrics for &lt;EM&gt;all&lt;/EM&gt; App Service Plans across &lt;EM&gt;all&lt;/EM&gt; subscriptions, how would you typically do that? As far as I know, most approaches require exporting this data into Splunk and then querying it from there.&lt;/P&gt;&lt;P&gt;But what if we had a solution that lets Splunk query Azure Monitor data &lt;STRONG&gt;directly&lt;/STRONG&gt;, in real time—without ingestion? Data would remain live in Azure, and Splunk would simply query it on demand, giving us more flexibility and control.&lt;/P&gt;&lt;P&gt;Think about scenarios where you want to run the same query across multiple Log Analytics workspaces. This solution makes that possible as well.&lt;/P&gt;&lt;P&gt;Personally, I prefer Splunk’s alerting capabilities over Azure’s. If we can query Azure Monitor data directly, we can also leverage Splunk alerts without needing to ingest anything first.&lt;/P&gt;&lt;P&gt;If anyone is interested, I’m happy to share the initial version of the app I’ve built.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Dec 2025 02:28:12 GMT</pubDate>
    <dc:creator>mrnobita</dc:creator>
    <dc:date>2025-12-11T02:28:12Z</dc:date>
    <item>
      <title>A splunk command to query Azure Monitor</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/A-splunk-command-to-query-Azure-Monitor/m-p/756396#M12074</link>
      <description>&lt;P&gt;Azure Monitor collects metrics and logs across many different resource types. For example, if you want to view CPU and memory metrics for &lt;EM&gt;all&lt;/EM&gt; App Service Plans across &lt;EM&gt;all&lt;/EM&gt; subscriptions, how would you typically do that? As far as I know, most approaches require exporting this data into Splunk and then querying it from there.&lt;/P&gt;&lt;P&gt;But what if we had a solution that lets Splunk query Azure Monitor data &lt;STRONG&gt;directly&lt;/STRONG&gt;, in real time—without ingestion? Data would remain live in Azure, and Splunk would simply query it on demand, giving us more flexibility and control.&lt;/P&gt;&lt;P&gt;Think about scenarios where you want to run the same query across multiple Log Analytics workspaces. This solution makes that possible as well.&lt;/P&gt;&lt;P&gt;Personally, I prefer Splunk’s alerting capabilities over Azure’s. If we can query Azure Monitor data directly, we can also leverage Splunk alerts without needing to ingest anything first.&lt;/P&gt;&lt;P&gt;If anyone is interested, I’m happy to share the initial version of the app I’ve built.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 02:28:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/A-splunk-command-to-query-Azure-Monitor/m-p/756396#M12074</guid>
      <dc:creator>mrnobita</dc:creator>
      <dc:date>2025-12-11T02:28:12Z</dc:date>
    </item>
  </channel>
</rss>

