All Apps and Add-ons

Error when ingesting Azure Monitor Diagnostic Log: no connection on hub docs:05

njytrde
Explorer

Hello,

I am trying to ingest Azure Activity Logs and Azure Diagnostic logs into our Splunk cloud environment. Per another question on Azure Activity logs, I was able to find out that I needed to have port 5671 for the Activity logs.

I had that done through my network team and am now getting the Activity logs, but NOT the Diagnostic logs.

This is the error I get:

06-15-2019 02:19:57.727 -0400 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-Azure_Monitor/bin/azure_diagnostic_logs.sh" Modular input azure_diagnostic_logs://New Azure Monitor Diagnostic Log No connection on hub: docs05. 

Is there a network route to the endpoint?

Also, this is through the Azure Monitor add-on, configured in Data Inputs. Please advise on what other port that I need open.

Thanks!

0 Karma

Priyankakumari1
Explorer

Hi, I am getting same, please let me know how you resolved this??

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...