All Apps and Add-ons

Error when ingesting Azure Monitor Diagnostic Log: no connection on hub docs:05



I am trying to ingest Azure Activity Logs and Azure Diagnostic logs into our Splunk cloud environment. Per another question on Azure Activity logs, I was able to find out that I needed to have port 5671 for the Activity logs.

I had that done through my network team and am now getting the Activity logs, but NOT the Diagnostic logs.

This is the error I get:

06-15-2019 02:19:57.727 -0400 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-Azure_Monitor/bin/" Modular input azure_diagnostic_logs://New Azure Monitor Diagnostic Log No connection on hub: docs05. 

Is there a network route to the endpoint?

Also, this is through the Azure Monitor add-on, configured in Data Inputs. Please advise on what other port that I need open.


0 Karma


Hi, I am getting same, please let me know how you resolved this??

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.