Splunk Alerting for Azure contents



I ingested some Azure data into splunk via event hub and would like to ask if you Could you please share some idea/alerts on Azure contents . If you have Azure/Splunk in your env , What are you alerting on based on Azure logs ? Could you share some of the Alerts contents ? 


Any help is much appreciated. 



