All Apps and Add-ons

Could not pull data through Micorsoft Azure Inventory Add-on app to splunk?

mthirumalareddy
Explorer

I have installed Microsoft Azure Inventory Add-on for Splunk and created and index " azure" and have added the inputs and have provided the Azure Subscription ID and Tenant ID. But I could not pull the logs from azure to Splunk. Can anyone help me in this?

Tags (1)
0 Karma

jconger
Splunk Employee
Splunk Employee

You will need to add the Azure AD application registration's Client ID (a.k.a. Application ID) and Client Secret (a.k.a. Key) by going to Configuration -> Add-on Settings.

Reference -> https://docs.microsoft.com/en-us/azure/active-directory/develop/howto-create-service-principal-porta...
Assign the application the Reader role to your subscription(s).

alt text

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...