<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which approch is easier to implement- installing Universal Forwarder(UF) or using the Splunk Add-on for Microsoft Cloud Services in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439368#M8316</link>
    <description>&lt;P&gt;In my opinion, the Splunk Add-on for Microsoft Cloud Services would be the better route.  As with any Splunk Add-on, you will have the added value of things like field extractions.  The Add-on also communicates via API, so I'm not even sure you could easily get at the same data.  Also, you would still have to configure a Universal Forwarder to point it at the data sources you want to ingest, with the added task of extracting fields.&lt;/P&gt;

&lt;P&gt;Here is a link to a blog post which helps with the configuration of the Add-on.  I have had a few customers successfully utilize this post when configuring the Add-on.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html"&gt;https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jul 2018 13:03:52 GMT</pubDate>
    <dc:creator>kmorris_splunk</dc:creator>
    <dc:date>2018-07-16T13:03:52Z</dc:date>
    <item>
      <title>Which approch is easier to implement- installing Universal Forwarder(UF) or using the Splunk Add-on for Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439367#M8315</link>
      <description>&lt;P&gt;from what I understood with Splunk Add-on for Microsoft Cloud Services, there are some configuration that I will have to perform, while with UF just an installation is required, which approach is preferred? and why?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 12:32:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439367#M8315</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-07-16T12:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Which approch is easier to implement- installing Universal Forwarder(UF) or using the Splunk Add-on for Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439368#M8316</link>
      <description>&lt;P&gt;In my opinion, the Splunk Add-on for Microsoft Cloud Services would be the better route.  As with any Splunk Add-on, you will have the added value of things like field extractions.  The Add-on also communicates via API, so I'm not even sure you could easily get at the same data.  Also, you would still have to configure a Universal Forwarder to point it at the data sources you want to ingest, with the added task of extracting fields.&lt;/P&gt;

&lt;P&gt;Here is a link to a blog post which helps with the configuration of the Add-on.  I have had a few customers successfully utilize this post when configuring the Add-on.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html"&gt;https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 13:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439368#M8316</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2018-07-16T13:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Which approch is easier to implement- installing Universal Forwarder(UF) or using the Splunk Add-on for Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439369#M8317</link>
      <description>&lt;P&gt;Thanks for the answer, but I still don't understand what is the benefit of using one over the other.&lt;BR /&gt;
let's assume I used UF before it's more familiar to me, why should I'll want to work with new configuration of the add on?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 14:51:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439369#M8317</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-07-16T14:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Which approch is easier to implement- installing Universal Forwarder(UF) or using the Splunk Add-on for Microsoft Cloud Services</title>
      <link>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439370#M8318</link>
      <description>&lt;P&gt;Thanks for the answer, but I still don't understand what is the benefit of using one over the other.&lt;BR /&gt;
let's assume I used UF before it's more familiar to me, why should I'll want to work with new configuration of the add on?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 14:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Which-approch-is-easier-to-implement-installing-Universal/m-p/439370#M8318</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-07-16T14:51:53Z</dc:date>
    </item>
  </channel>
</rss>

