<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pull Azure event hub logs to Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744046#M118205</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you arent on Splunk Cloud and you're team say it isnt possible (for whatever reason) to use Push based approach then I would recommend using the&amp;nbsp;Splunk Add-on for Microsoft Cloud Services app.&lt;/P&gt;&lt;P&gt;This aligns with the recommendations here:&amp;nbsp;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub_data" target="_blank" rel="noopener nofollow noreferrer"&gt;https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2025 21:06:01 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-04-11T21:06:01Z</dc:date>
    <item>
      <title>pull Azure event hub logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744024#M118199</link>
      <description>&lt;P&gt;How can we pull&amp;nbsp;Azure event hub logs to Splunk? I check that we cannot use HEC configuration for pulling the data. When I was checking for apps, there are 3-4 apps present for this: but I have found most of them are not supported now and older version. I found this app -&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3110" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3110&lt;/A&gt;. Not sure how to configure this? Is there any other add-on or approach we can follow to pull event hubs Azure logs to Splunk? Any leads would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 15:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744024#M118199</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-04-11T15:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: pull Azure event hub logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744026#M118200</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/AzureGDI" target="_self"&gt;The docs&lt;/A&gt; state "&lt;SPAN&gt;As a general rule,&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="http://docs.splunk.com/Documentation/DM/1.12.2/User/About" target="_blank" rel="noopener"&gt;Data Manager&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;is the recommended method of data ingestion for Splunk Cloud customers for&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="http://docs.splunk.com/Documentation/DM/1.12.2/User/GDIOverview" target="_blank" rel="noopener"&gt;supported data sources&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;where available" Are you using Splunk Cloud?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Its also worth checking the following Lantern docs&amp;nbsp;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub_data" target="_blank" rel="noopener"&gt;https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub_data&lt;/A&gt;&amp;nbsp;as an alternative - this uses&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3110" target="_self"&gt;Splunk Add-on for Microsoft Cloud Services&lt;/A&gt;&amp;nbsp;which you've already referrenced.&lt;/P&gt;&lt;P&gt;Either of these options are good contenders. Alternatively there is a third option, which is to use HEC and Azure Functions to push the data. Check out&amp;nbsp;&lt;A href="https://github.com/splunk/azure-functions-splunk/blob/master/event-hubs-hec/README.md" target="_blank" rel="noopener"&gt;https://github.com/splunk/azure-functions-splunk/blob/master/event-hubs-hec/README.md&lt;/A&gt;&amp;nbsp;for more information around this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ultimately the best option for you depends on a number of factors - such as Cloud/Enterprise but also if you have the engineering support for things like Azure Functions etc.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 16:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744026#M118200</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-11T16:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: pull Azure event hub logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744034#M118201</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;'s answer is a good one.&lt;/P&gt;&lt;P&gt;In general, HEC cannot pull data from any source.&amp;nbsp; It is merely a receiver for data pushed to Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 16:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744034#M118201</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-11T16:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: pull Azure event hub logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744035#M118202</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; Splunk enterprise not Splunk Cloud.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 16:36:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744035#M118202</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-04-11T16:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: pull Azure event hub logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744036#M118203</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;according to you what will be the best approach for us? Ours is Splunk enterprise and our Splunk instances residing on AWS cloud. Azure team confirmed that pushing is not possible.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 16:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744036#M118203</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-04-11T16:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: pull Azure event hub logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744043#M118204</link>
      <description>&lt;P&gt;Install the app you cited in the OP on a heavy forwarder and use that to pull data from Azure using API calls.&amp;nbsp; The HF will forward the data to Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 18:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744043#M118204</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-11T18:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: pull Azure event hub logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744046#M118205</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you arent on Splunk Cloud and you're team say it isnt possible (for whatever reason) to use Push based approach then I would recommend using the&amp;nbsp;Splunk Add-on for Microsoft Cloud Services app.&lt;/P&gt;&lt;P&gt;This aligns with the recommendations here:&amp;nbsp;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub_data" target="_blank" rel="noopener nofollow noreferrer"&gt;https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 21:06:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pull-Azure-event-hub-logs-to-Splunk/m-p/744046#M118205</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-11T21:06:01Z</dc:date>
    </item>
  </channel>
</rss>

