<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does anyone have experience with using Data Manager for Azure and Splunk ES? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-experience-with-using-Data-Manager-for-Azure/m-p/620654#M106939</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/100202"&gt;@Junie&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in a recent project, I preferred to use for Data ingestion some Add-Ons as:&lt;/P&gt;&lt;P&gt;Splunk Add-On for Microsoft Office 365 (&lt;A href="https://splunkbase.splunk.com/app/4055" target="_blank"&gt;https://splunkbase.splunk.com/app/4055&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Splunk Add-On for Microsoft Azure (&lt;A href="https://splunkbase.splunk.com/app/3757" target="_blank"&gt;https://splunkbase.splunk.com/app/3757&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sat, 12 Nov 2022 10:25:06 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-11-12T10:25:06Z</dc:date>
    <item>
      <title>Does anyone have experience with using Data Manager for Azure and Splunk ES?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-experience-with-using-Data-Manager-for-Azure/m-p/620636#M106937</link>
      <description>&lt;P&gt;Hi there!&amp;nbsp; I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.&lt;/P&gt;
&lt;P&gt;According to this link &lt;A href="https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure&lt;/A&gt; it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.&lt;/P&gt;
&lt;P&gt;The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub).&amp;nbsp; Does DM contain that sourcetype needed for the ES stories?&amp;nbsp; Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 19:00:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-experience-with-using-Data-Manager-for-Azure/m-p/620636#M106937</guid>
      <dc:creator>Junie</dc:creator>
      <dc:date>2022-11-11T19:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have experience with using Data Manager for Azure and Splunk ES?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-experience-with-using-Data-Manager-for-Azure/m-p/620654#M106939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/100202"&gt;@Junie&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in a recent project, I preferred to use for Data ingestion some Add-Ons as:&lt;/P&gt;&lt;P&gt;Splunk Add-On for Microsoft Office 365 (&lt;A href="https://splunkbase.splunk.com/app/4055" target="_blank"&gt;https://splunkbase.splunk.com/app/4055&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Splunk Add-On for Microsoft Azure (&lt;A href="https://splunkbase.splunk.com/app/3757" target="_blank"&gt;https://splunkbase.splunk.com/app/3757&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2022 10:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-experience-with-using-Data-Manager-for-Azure/m-p/620654#M106939</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-12T10:25:06Z</dc:date>
    </item>
  </channel>
</rss>

