<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to send data to Splunk from Azure Event Hub? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-to-Splunk-from-Azure-Event-Hub/m-p/618022#M106652</link>
    <description>&lt;P&gt;Hello there!&lt;/P&gt;
&lt;P&gt;I've been ingesting data from Azure Storage Explorer via the Splunk Add-On for Microsoft Cloud Services app, however, I now wish to ingest data from an Azure Event Hub.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know I can either create an input in the same app or use the Microsoft Azure Add-on for Splunk app.&amp;nbsp; Is there a way to specify which partition to collect data from?&amp;nbsp; Furthermore, is there a way to send data to different indexes and sourcetypes from 1 Event Hub?&lt;/P&gt;
&lt;P&gt;I'm working on Splunk Cloud, so I currently don't have access to config files.&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Oct 2022 19:54:52 GMT</pubDate>
    <dc:creator>pcontreras</dc:creator>
    <dc:date>2022-10-21T19:54:52Z</dc:date>
    <item>
      <title>How to send data to Splunk from Azure Event Hub?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-to-Splunk-from-Azure-Event-Hub/m-p/618022#M106652</link>
      <description>&lt;P&gt;Hello there!&lt;/P&gt;
&lt;P&gt;I've been ingesting data from Azure Storage Explorer via the Splunk Add-On for Microsoft Cloud Services app, however, I now wish to ingest data from an Azure Event Hub.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know I can either create an input in the same app or use the Microsoft Azure Add-on for Splunk app.&amp;nbsp; Is there a way to specify which partition to collect data from?&amp;nbsp; Furthermore, is there a way to send data to different indexes and sourcetypes from 1 Event Hub?&lt;/P&gt;
&lt;P&gt;I'm working on Splunk Cloud, so I currently don't have access to config files.&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 19:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-to-Splunk-from-Azure-Event-Hub/m-p/618022#M106652</guid>
      <dc:creator>pcontreras</dc:creator>
      <dc:date>2022-10-21T19:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data to Splunk from Azure Event Hub?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-to-Splunk-from-Azure-Event-Hub/m-p/618914#M106753</link>
      <description>&lt;P&gt;if you're familiar with Azure Logic Apps, you could consider using those to get events from the Event Hub and push them to a Splunk HEC input. The logic app can then also contain some logic to assign different index/sourcetype etc. to the data (as part of the HEC metadata fields).&lt;/P&gt;&lt;P&gt;I just noticed someone also built a Splunk App around that approach:&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/6223" target="_blank"&gt;https://splunkbase.splunk.com/app/6223&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 13:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-to-Splunk-from-Azure-Event-Hub/m-p/618914#M106753</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2022-10-31T13:00:05Z</dc:date>
    </item>
  </channel>
</rss>

