All Apps and Add-ons

Is there any plan to pull Azure Security Center logs and alerts from Splunk Add-on for Microsoft Cloud Services?

swong2
Path Finder

Is there any plan or in a roadmap to support pulling Azure Security Center logs/alerts as mentioned in this Microsoft article https://docs.microsoft.com/en-us/azure/security/security-azure-log-integration-overview.

jconger
Splunk Employee
Splunk Employee

These logs should show up in the Audit.General schema, which is supported in the 2.1 version of the MS Cloud Services add-on -> https://splunkbase.splunk.com/app/3110/

smitra_splunk
Splunk Employee
Splunk Employee

is it the mscs:azure:audit sourcetype ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...