<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TA-Azure data inputs configuration in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205742#M98781</link>
    <description>&lt;P&gt;Thank you ... Running 6.4.0 and we see the standard 5 items&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Files &amp;amp; directories&lt;/LI&gt;
&lt;LI&gt;TCP&lt;/LI&gt;
&lt;LI&gt;UDP&lt;/LI&gt;
&lt;LI&gt;Scripts&lt;/LI&gt;
&lt;LI&gt;Database inputs&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 04 Aug 2016 15:17:20 GMT</pubDate>
    <dc:creator>pkeller</dc:creator>
    <dc:date>2016-08-04T15:17:20Z</dc:date>
    <item>
      <title>TA-Azure data inputs configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205740#M98779</link>
      <description>&lt;P&gt;The instructions for configuring data inputs for the TA-Azure imply that there should be additional items under Settings -&amp;gt; Data Inputs. We're not seeing them. We've installed and enabled the TA but can't proceed with the &lt;STRONG&gt;highlighted&lt;/STRONG&gt; step (below) from the documentation because neither "Azure Diagnostics" nor "Azure Website Diagnostics" input appears in standard Data Inputs panel.&lt;/P&gt;

&lt;P&gt;[ snipped from Azure setup document ]&lt;/P&gt;

&lt;P&gt;Setting up Splunk to read Azure diagnostic logs&lt;/P&gt;

&lt;P&gt;Within Splunk, click Settings -&amp;gt; Data inputs&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Click the "Azure Diagnostics" input or "Azure Website Diagnostics" input&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Click on the "New" button to create a new data input&lt;BR /&gt;
Give the input a unique name&lt;BR /&gt;
Supply the name of the Azure Storage account containing the log data&lt;BR /&gt;
Supply the Azure Storage account access key - refer to the section below for details on how to obtain your storage account access key&lt;/P&gt;

&lt;P&gt;Is there some other setup item that needs to be performed in order to complete the Data inputs portion for the Azure TA?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 15:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205740#M98779</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2016-08-04T15:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: TA-Azure data inputs configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205741#M98780</link>
      <description>&lt;P&gt;What version of Splunk are you running and what other inputs do you see?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 15:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205741#M98780</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2016-08-04T15:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: TA-Azure data inputs configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205742#M98781</link>
      <description>&lt;P&gt;Thank you ... Running 6.4.0 and we see the standard 5 items&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Files &amp;amp; directories&lt;/LI&gt;
&lt;LI&gt;TCP&lt;/LI&gt;
&lt;LI&gt;UDP&lt;/LI&gt;
&lt;LI&gt;Scripts&lt;/LI&gt;
&lt;LI&gt;Database inputs&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 04 Aug 2016 15:17:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205742#M98781</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2016-08-04T15:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: TA-Azure data inputs configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205743#M98782</link>
      <description>&lt;P&gt;I've been working on this most of the day and this is what I found.&lt;/P&gt;

&lt;P&gt;Installing the TA on a 6.4.2 system ( upgraded from 6.3.2 ) results in no modifications to the "Settings -&amp;gt; Data Inputs" panel.&lt;/P&gt;

&lt;P&gt;In addition, the blog &lt;A href="http://blogs.splunk.com/tag/azure/"&gt;http://blogs.splunk.com/tag/azure/&lt;/A&gt; suggests that we should be seeing a "Local Inputs" header under "Settings -&amp;gt; Data Inputs" ... That's not the case in any of our 6.4.x 'upgraded' infrastructure.&lt;/P&gt;

&lt;P&gt;After doing a fresh install of 6.4.2, I now see the "Local Inputs" and Forwarded Inputs headers under "Settings -&amp;gt; Data Inputs" ... I believe that somewhere in the upgrade process, the migration steps performed must have missed the changes required here.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 22:01:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205743#M98782</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2016-08-04T22:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: TA-Azure data inputs configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205744#M98783</link>
      <description>&lt;P&gt;I believe my issue was that the "SplunkLightForwarder" app had been enabled on this host. ( SplunkForwarder was also enabled ) ... I disabled the app, restarted Splunk, and now the Data Inputs panel looks the way it is described in the documentation.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 15:41:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205744#M98783</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2016-08-05T15:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: TA-Azure data inputs configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205745#M98784</link>
      <description>&lt;P&gt;Ultimately, this was caused because the dbConnect app (v 1.x) contains a datainputstats.html file which was taking precedence over the 6.4.x file with the same name under $SPLUNK_HOME/share/splunk/search_mrsparkle/templates/admin/datainputstats.html&lt;/P&gt;

&lt;P&gt;I replaced the html file under the dbx tree with the one from search_mrsparkle, bounced splunkd and all looks good now.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TA-Azure-data-inputs-configuration/m-p/205745#M98784</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2020-09-29T10:29:21Z</dc:date>
    </item>
  </channel>
</rss>

