Hi there,
Anyone pls advice how to onboard VM logs and Bastion logs from Azure to Splunk. I have installed the add on microsoft cloud services but am only receiving metrics log from these bastion event hub and VM event hub. Please let me know how to get VM logs and Bastion logs from azure to Splunk
thanks in advance
Hi Aleena,
When configuring Diagnostic settings for resources such as Azure Bastion, you can choose which"category" of data to forward/export to a destination such as an event hub. For example, the two categories of data for Azure bastion are:
You need to edit the Diagnostic Settings to also forward the above audit logs to an event hub.