All Apps and Add-ons

No Data from inputs

Kendo213
Communicator

I've configured each input, however I am seeing no data, and no errors in the _internal logs for the heavy forwarder. What additional troubleshooting can I do?

0 Karma

jconger
Splunk Employee
Splunk Employee

Are you using this add-on - https://splunkbase.splunk.com/app/3534/ ?
If so, have you configured the Azure side to send data to an event hub and set up an Azure application and key vault - https://www.splunk.com/blog/2018/04/20/splunking-microsoft-azure-monitor-data-part-1-azure-setup.htm... ?

FYI, you can use a script to automate the Azure setup -> https://github.com/Microsoft/AzureMonitorAddonForSplunk/tree/master/scripts

0 Karma

Kendo213
Communicator

I ended up reviewing firewall logs and noticed it's blocking some of the TLS ports. Also, the Python changes required for this Add-on broke the Add-on for JMX Extensions unfortunately. I guess we're going to have to put the Azure Add-on on its own HF.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...