All Apps and Add-ons

Splunk Add-on for Microsoft Azure: Where are connection log files stored?

SwiftSolves
New Member

I have a Splunk instance up and running and I have installed a Azure Connector to retrieve azure audit logs against Azure Government Cloud. I have modified AzureAudit.py on the Splunk server, but still getting a message "waiting for Data..." when searching against the data summary

Because the Splunk connector calls Azure Insights REST API, is their a way to read log files on these REST API calls to see what is failing? Do connectors in general store log files in /opt/splunk/var/log/splunk ? Or maybe a different directory or log file?

0 Karma

jconger
Splunk Employee
Splunk Employee

To get detailed information, set the logging level to DEBUG in the AzureAudit.py file (it is set to ERROR by default). Then, you can search the _internal index for detailed messages.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...