All Apps and Add-ons

Azure Monitor Metrics in event hub but not appearing in Splunk

devsupport
Engager

We configured the Azure Monitor Metrics input and configured diagnostics to send metrics (and logs) to our event hub. We are only seeing 2 amm_resourceTypes when there should be more (ex. Load Balancer). Using Service Bus Explorer, we can see expected metrics data in the event hub.

After reading through the docs on GitHub, I do not see any additional configuration required to pull other Azure resource type metrics. Should the add-on automatically handle all/most resource types?

We're using add-on version 1.3.1.

0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

The Metrics input in the Azure Monitor Ad-on uses a REST API to get the metrics data rather than event hubs (the Activity input and the Diagnostic input do use event hubs though). There are 2 parts to the metrics input:

  1. Configure the input in Splunk (tenant ID, app ID/key, subscription ID, vault information).
  2. Tag the resource(s) you want with a "metrics" tag. The value of the tag should be the metric(s) you want to collect. More information here -> https://github.com/Microsoft/AzureMonitorAddonForSplunk/wiki/Configuration-of-Azure#metrics

Here is a good reference on the metics available from Azure Monitor that can be ingested into Splunk -> https://docs.microsoft.com/en-us/azure/azure-monitor/platform/metrics-supported

View solution in original post

0 Karma

jconger
Splunk Employee
Splunk Employee

The Metrics input in the Azure Monitor Ad-on uses a REST API to get the metrics data rather than event hubs (the Activity input and the Diagnostic input do use event hubs though). There are 2 parts to the metrics input:

  1. Configure the input in Splunk (tenant ID, app ID/key, subscription ID, vault information).
  2. Tag the resource(s) you want with a "metrics" tag. The value of the tag should be the metric(s) you want to collect. More information here -> https://github.com/Microsoft/AzureMonitorAddonForSplunk/wiki/Configuration-of-Azure#metrics

Here is a good reference on the metics available from Azure Monitor that can be ingested into Splunk -> https://docs.microsoft.com/en-us/azure/azure-monitor/platform/metrics-supported

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...