<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Running Splunk in Azure (or any cloud environment) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89434#M18558</link>
    <description>&lt;P&gt;I just wrote an Azure Diagnostics App for Splunk and submitted it to splunkbase yesterday for approval. I tested it in both windows and Linux. What it does is pull the azure diagnostics from the azure WAD tables and populate the splunk indexes with it. Currently it doesn't do any grooming of the azure tables but that is something I plan on adding later. It can run on or off-premises, some due diligence is needed to determine what makes the most sense in different scenarios (pay for instances vs data transfers). If you do decide to give it a try, do let me know, I'd love to hear some feedback.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Michel&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jan 2012 01:29:24 GMT</pubDate>
    <dc:creator>merc_sw</dc:creator>
    <dc:date>2012-01-17T01:29:24Z</dc:date>
    <item>
      <title>Running Splunk in Azure (or any cloud environment)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89431#M18555</link>
      <description>&lt;P&gt;Wondering if there are any best practices (or reference architectures) for running Splunk against an Azure (or another cloud) solution where there are, for example, multiple web servers, and in this case a very large number of worker nodes. There could also be n number of these deployments. So essentially LOTS of cloud VM instances. All the logs are automatically transferred to Azure Table Storage.&lt;/P&gt;

&lt;P&gt;We don't want to have to transfer all this data on-premise as it could get a little unwieldy.&lt;/P&gt;

&lt;P&gt;Would the best approach be to run Splunk up on a VM in the cloud and have it download the logs to local storage? This could be problematic if the VM was recycled as the local storage could (will eventually) get wiped...&lt;/P&gt;

&lt;P&gt;Appreciate any guidance.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Dave&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2011 00:40:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89431#M18555</guid>
      <dc:creator>davefellows</dc:creator>
      <dc:date>2011-04-27T00:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Running Splunk in Azure (or any cloud environment)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89432#M18556</link>
      <description>&lt;P&gt;There has definitely been some work done on this before, and I believe Splunk's SEs have used Amazon-based instances for demos from time to time.&lt;/P&gt;

&lt;P&gt;The following would be a good starting point:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://blogs.splunk.com/2011/02/24/splunk-and-ec2/"&gt;Splunk and EC2&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://blogs.splunk.com/2008/06/17/splunk-ninja-cloud-power-splunkin-with-amazons-ec2/"&gt;Splunk Ninja - Cloud Power - Splunkin' With Amazon's EC2&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://splunkninja.ning.com/forum/topics/splunk-architecture-for"&gt;Splunk Architecture for Multiple Hybrid Clouds&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 28 Apr 2011 18:32:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89432#M18556</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-04-28T18:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: Running Splunk in Azure (or any cloud environment)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89433#M18557</link>
      <description>&lt;P&gt;Thanks. I did watch a couple of those. After doing further research I believe using Universal Forwarders (I wasn't aware of these when posting) on each node and hosting one or more indexers in the cloud is the way to go. Would certainly appreciate any comments on this approach though.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2011 21:27:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89433#M18557</guid>
      <dc:creator>davefellows</dc:creator>
      <dc:date>2011-04-28T21:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Running Splunk in Azure (or any cloud environment)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89434#M18558</link>
      <description>&lt;P&gt;I just wrote an Azure Diagnostics App for Splunk and submitted it to splunkbase yesterday for approval. I tested it in both windows and Linux. What it does is pull the azure diagnostics from the azure WAD tables and populate the splunk indexes with it. Currently it doesn't do any grooming of the azure tables but that is something I plan on adding later. It can run on or off-premises, some due diligence is needed to determine what makes the most sense in different scenarios (pay for instances vs data transfers). If you do decide to give it a try, do let me know, I'd love to hear some feedback.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Michel&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2012 01:29:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89434#M18558</guid>
      <dc:creator>merc_sw</dc:creator>
      <dc:date>2012-01-17T01:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Running Splunk in Azure (or any cloud environment)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89435#M18559</link>
      <description>&lt;P&gt;Setting up UniversalForwarders on each node should work just fine. However, since Azure diagnostics logs might always have more information, I want to have this data indexed. Did you figure out the best way to forward azure diagnostics logs to a Splunk indexer (OnPrem or on Azure)?&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 22:52:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89435#M18559</guid>
      <dc:creator>anirudh_veldurt</dc:creator>
      <dc:date>2014-05-08T22:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Running Splunk in Azure (or any cloud environment)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89436#M18560</link>
      <description>&lt;P&gt;Quite some time has passed since this was originally posted, but here are some pointers:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Deploying Splunk in Azure: &lt;A href="http://blogs.splunk.com/2016/02/18/announcing-splunk-enterprise-in-microsoft-azure-marketplace/"&gt;http://blogs.splunk.com/2016/02/18/announcing-splunk-enterprise-in-microsoft-azure-marketplace/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Pulling Azure Diagnostics into Splunk: &lt;A href="http://blogs.splunk.com/2016/03/15/splunking-microsoft-azure-data/"&gt;http://blogs.splunk.com/2016/03/15/splunking-microsoft-azure-data/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Pulling Azure Audit data into Splunk: &lt;A href="http://blogs.splunk.com/2016/03/28/splunking-microsoft-azure-audit-data/"&gt;http://blogs.splunk.com/2016/03/28/splunking-microsoft-azure-audit-data/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;To monitor Azure VMs, in many cases, you do not need to install &amp;amp; configure UF on each node. Instead, you can rely on &lt;A href="https://azure.microsoft.com/en-us/documentation/articles/azure-diagnostics/"&gt;Azure Diagnostics &lt;/A&gt; (performance metrics, logs, etc.) that are collected out of the box and stored in Azure Storage account. You can then ingest this data into Splunk (be it on-prem or on Azure) in various ways, including &lt;A href="https://splunkbase.splunk.com/app/3084"&gt;Splunk Add-on for Microsoft Azure&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 04:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-Splunk-in-Azure-or-any-cloud-environment/m-p/89436#M18560</guid>
      <dc:creator>rarsan_splunk</dc:creator>
      <dc:date>2016-04-28T04:56:53Z</dc:date>
    </item>
  </channel>
</rss>

