All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services - Data over ExpressRoute

MarcoAlves
New Member

Running the specific scenario:

1 Splunk heavy forwarder with no direct internet access (on-prem Splunk 8.1.7.2)

Splunk Add-on for Microsoft Cloud Services on the HF (4.3.3)

1 internet proxy

Express route for private network traffic to Azure

 

When trying to ingest data from an event hub input on the above setup with the proxy configuration enabled on the add-on:

1 - Service principal authentication succeeds (over internet proxy as expected)

2 - Connection to event hub fails because the event hub only accepts connections over the express route link and the heavy forwarder tries to connect through a public IP using the configured proxy - I've confirmed the HF resolves the event hub FQDN to a private IP but it still sends the connection request to the proxy. I've also confirmed this on the add-on code.

When trying to ingest data from an event hub input on the above setup with the proxy configuration disabled on the add-on:

1 - Service principal authentication fails (no internet access)

 

In the above scenario, the add-on needs internet access to get an authentication token from the Microsoft API, but the connection to the event hub to ingest data needs to happen through the express route private link. The Add-on just seems to do all one way or the other depending on the proxy configuration being enabled or not. Is there a solution for this?

Having the proxy configuration enabled also breaks all storage account inputs as they use a SAS key (no internet required for authentication) but are not routed through the express route link despite the storage account FQDN being resolved into a private IP.

Regards,

Marco

Labels (2)
0 Karma

SplunkingKnight
Explorer

Hello MarcoAlves,

did you find a solution for this?

Regards

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...