- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If we are only adding an event hub input using the Microsoft Azure Add-on for Splunk, do we need to include account information on the configuration tab?
We haven't put in any account information on the configuration tab and are only using an event hub input, but we aren't seeing any data coming in.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


You do not need the account information for the Event Hub input. The account information is necessary for the other inputs as they use REST APIs, and the account is used to authenticate to those APIs. The Event Hub input only needs the connection string (no account).
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


You do not need the account information for the Event Hub input. The account information is necessary for the other inputs as they use REST APIs, and the account is used to authenticate to those APIs. The Event Hub input only needs the connection string (no account).
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any other places to check as to why we are not seeing data come in to Splunk?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Here are the 3 most common issues:
- Using a Splunk 8 instance - the Event Hub input does not work on Splunk 8 (yet)
- Entering an Event Hub key instead of an Event Hub connection string
- Entering an Event Hub Namespace instead of an individual Event Hub Name
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Jason. It appears that our problem might be firewall related.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Confirmed that this all works after the firewall was opened up. We had to open our heavy forwarder to be able to reach port 5671.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is your splunk version? I am having issue but my splunk is also in Azure and I am on 8.0.3 version.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Our Splunk version is 7.2.7. The event hub collector is not compatible with Splunk 8. See @jconger response above.
