All Apps and Add-ons

How can I validate Azure Storage account connected with the Splunk Add-on for Microsoft Cloud Services.

pratapa
Explorer

Hi,

We have a requirement to monitor Azure logs from Splunk.

 

For that we need to complete the following steps.

 

1. Configure a Storage Account in Microsoft Cloud Service.
2. Connect to your Azure Storage account with the Splunk Add-on for Microsoft Cloud  Services.
3. Configure inputs.conf file.
 
https://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/Configureinputs5
 
1. Configure a Storage Account in Microsoft Cloud Service. -- completed
 

Storage account name:aeadsplunklog

key1: +e7xkNRz5S8XBgnX1IEfMHiJqWrjpuxu2HQg30jmhe/EvjLOR+BoK5thr2aBfPanNkAINgqXuphMbGxNwdl7uA==

2. Connect to your Azure Storage account with the Splunk Add-on for Microsoft Cloud  Services.

We have configured mscs_storage_accounts.conf under /opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/local

[root@indexer server]# cat mscs_storage_accounts.conf

account_name = aeadsplunklog
account_secret = +e7xkNRz5S8XBgnX1IEfMHiJqWrjpuxu2HQg30jmhe/EvjLOR+BoK5thr2aBfPanNkAINgqXuphMbGxNwdl7uA==
account_secret_type = 1
account_class_type = 1

 

Restarted Spunk.

 

Now how can I validate that Azure storage account is connected with the Splunk Add-on for Microsoft Cloud  Services.

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...