<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to get Logs from Azure servers to On-prem splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343366#M63224</link>
    <description>&lt;P&gt;Yes. Assuming you have network connectivity and the hosts in Azure can reach port 8089 on the deployment server.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Dec 2017 15:21:36 GMT</pubDate>
    <dc:creator>baldwintm</dc:creator>
    <dc:date>2017-12-14T15:21:36Z</dc:date>
    <item>
      <title>how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343359#M63217</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;What is the best way to get windows logs and linux logs from aroung 200+ servers in Azure to on-prem splunk environment, I tried the blob storage option but its not in correct format. is it better to Install universal forwarders on cloud servers and forward them to on-prem indexers. any one had similar issue?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 16:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343359#M63217</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-12-12T16:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343360#M63218</link>
      <description>&lt;P&gt;hello @kiran331,&lt;/P&gt;

&lt;P&gt;are you using the app for mscs &lt;A href="https://splunkbase.splunk.com/app/3110/#/overview"&gt;https://splunkbase.splunk.com/app/3110/#/overview&lt;/A&gt;&lt;BR /&gt;
did you configure the Azure modular input?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343360#M63218</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-12-12T17:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343361#M63219</link>
      <description>&lt;P&gt;Yes, I'm getting the Azure audit logs  and resource logs, I'm looking for security, system and application logs from the windows servers in azure&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343361#M63219</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-12-12T17:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343362#M63220</link>
      <description>&lt;P&gt;looks like you are on the right track, &lt;BR /&gt;
read here:&lt;BR /&gt;
&lt;A href="https://www.splunk.com/blog/2016/03/15/splunking-microsoft-azure-data.html"&gt;https://www.splunk.com/blog/2016/03/15/splunking-microsoft-azure-data.html&lt;/A&gt;&lt;BR /&gt;
did you enable the correct audit rules on your azure account?&lt;BR /&gt;
check out these links: (also directly from article above)&lt;BR /&gt;
&lt;A href="https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-overview-of-diagnostic-logs"&gt;https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-overview-of-diagnostic-logs&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://msdn.microsoft.com/en-us/library/azure/dn931934.aspx"&gt;https://msdn.microsoft.com/en-us/library/azure/dn931934.aspx&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343362#M63220</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-12-12T17:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343363#M63221</link>
      <description>&lt;P&gt;Hey Kiran!&lt;/P&gt;

&lt;P&gt;I will be working with the MS Azure team shortly after the new year to ensure that Splunking Azure gets the first class treatment like we have in AWS! Once I have met with them I will be sure to check back with you. Until then, let us know what you find!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 14:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343363#M63221</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-12-13T14:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343364#M63222</link>
      <description>&lt;P&gt;I’ve found that the best way to get logs from servers in azure is to install the universal forwarder on the instances. &lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 00:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343364#M63222</guid>
      <dc:creator>baldwintm</dc:creator>
      <dc:date>2017-12-14T00:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343365#M63223</link>
      <description>&lt;P&gt;are you able to manage forwarders with on-prem deployment server?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 15:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343365#M63223</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-12-14T15:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343366#M63224</link>
      <description>&lt;P&gt;Yes. Assuming you have network connectivity and the hosts in Azure can reach port 8089 on the deployment server.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 15:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343366#M63224</guid>
      <dc:creator>baldwintm</dc:creator>
      <dc:date>2017-12-14T15:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343367#M63225</link>
      <description>&lt;P&gt;Is it  a best practice to talk to 8089 over internet with public Ip?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 15:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343367#M63225</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-12-14T15:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343368#M63226</link>
      <description>&lt;P&gt;That's a good question. &lt;BR /&gt;
It's https, so it would be encrypted, but then getting the data back to the indexers would be a little interesting.&lt;/P&gt;

&lt;P&gt;I'm not sure I have a good answer for you&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 15:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343368#M63226</guid>
      <dc:creator>baldwintm</dc:creator>
      <dc:date>2017-12-14T15:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343369#M63227</link>
      <description>&lt;P&gt;Yep you could do this, it would just be a good idea to flip off of Splunk default certs to 3rd party or self-signed certs for both the management port (8089) and for the forwarding layer (ie. 9997)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 19:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343369#M63227</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-12-14T19:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343370#M63228</link>
      <description>&lt;P&gt;I would recommend installing UF on the servers and forward the logs to your Splunk instance, that way you also have better control on how you want to parse the data. Using the blob storage may not give that flexibility. &lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 11:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/343370#M63228</guid>
      <dc:creator>varadredgntn</dc:creator>
      <dc:date>2017-12-18T11:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: how to get Logs from Azure servers to On-prem splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/680135#M113631</link>
      <description>&lt;P&gt;Looking for the solution. Would you mind if you resolve this issue, getting&amp;nbsp; Azure applciaion log to On-prem Splunk&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2024 00:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-get-Logs-from-Azure-servers-to-On-prem-splunk/m-p/680135#M113631</guid>
      <dc:creator>ppadhi01</dc:creator>
      <dc:date>2024-03-09T00:03:17Z</dc:date>
    </item>
  </channel>
</rss>

