<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk and Azure SQL audit via Event Hub in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-Azure-SQL-audit-via-Event-Hub/m-p/544273#M154170</link>
    <description>&lt;P&gt;I'm not sure how to even troubleshoot this.&lt;/P&gt;&lt;P&gt;A few weeks ago, we started a dropoff in events into splunk.&amp;nbsp; &amp;nbsp;We are sending Azure SQL Server audit logs via event hub picked up by Azure Add-on for Splunk.&amp;nbsp; &amp;nbsp;our traffic has NOT changed.&amp;nbsp; &amp;nbsp;Our HF has not changed.&lt;/P&gt;&lt;P&gt;I can't see my activity anymore (a month ago i saw everything I did).&amp;nbsp; &amp;nbsp;Now, i have no visibility to my traffic.&amp;nbsp; &amp;nbsp;I am seeing traffic from web servers and some other users, but not sure i trust it now.&amp;nbsp; &amp;nbsp;There has been a drop off in events.&lt;/P&gt;&lt;P&gt;What can I do to troubleshoot what is going on here?&amp;nbsp; I can turn on verbose logging, but since i can't throttle or specify what is getting logged (server log, not db log), it would be 000s of messages in a very heavily used database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 01:03:55 GMT</pubDate>
    <dc:creator>zippo706</dc:creator>
    <dc:date>2021-03-18T01:03:55Z</dc:date>
    <item>
      <title>Splunk and Azure SQL audit via Event Hub</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-Azure-SQL-audit-via-Event-Hub/m-p/544273#M154170</link>
      <description>&lt;P&gt;I'm not sure how to even troubleshoot this.&lt;/P&gt;&lt;P&gt;A few weeks ago, we started a dropoff in events into splunk.&amp;nbsp; &amp;nbsp;We are sending Azure SQL Server audit logs via event hub picked up by Azure Add-on for Splunk.&amp;nbsp; &amp;nbsp;our traffic has NOT changed.&amp;nbsp; &amp;nbsp;Our HF has not changed.&lt;/P&gt;&lt;P&gt;I can't see my activity anymore (a month ago i saw everything I did).&amp;nbsp; &amp;nbsp;Now, i have no visibility to my traffic.&amp;nbsp; &amp;nbsp;I am seeing traffic from web servers and some other users, but not sure i trust it now.&amp;nbsp; &amp;nbsp;There has been a drop off in events.&lt;/P&gt;&lt;P&gt;What can I do to troubleshoot what is going on here?&amp;nbsp; I can turn on verbose logging, but since i can't throttle or specify what is getting logged (server log, not db log), it would be 000s of messages in a very heavily used database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 01:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-Azure-SQL-audit-via-Event-Hub/m-p/544273#M154170</guid>
      <dc:creator>zippo706</dc:creator>
      <dc:date>2021-03-18T01:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and Azure SQL audit via Event Hub</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-Azure-SQL-audit-via-Event-Hub/m-p/547930#M155374</link>
      <description>&lt;P&gt;Azure Event Hub connectivity was recently deprecated in the Azure Add-on for Splunk. That functionality has been moved to the&amp;nbsp;Splunk Add-on for Microsoft Cloud Services (&lt;A href="https://splunkbase.splunk.com/app/3110/)" target="_blank"&gt;https://splunkbase.splunk.com/app/3110/)&lt;/A&gt;. Not saying there isn't another issue causing the drop-off, but it might be worth investigating moving that Event Hub connection to the other add-on.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 18:07:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-Azure-SQL-audit-via-Event-Hub/m-p/547930#M155374</guid>
      <dc:creator>masonwillinger</dc:creator>
      <dc:date>2021-04-14T18:07:26Z</dc:date>
    </item>
  </channel>
</rss>

