All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services _TCP_ROUTING

New Member

I am running Splunk Add-on for Microsoft Cloud Services on a Splunk Heavy Forwarder and I'm trying to forward the azure audit log to two splunk instances. The problem is that it only forwards it to the default output. I have tried this:

account = AZURE
interval = 300
start_time = 2019-10-19T13:00:34+02:00
subscription_id =
disabled = 0
_TCP_ROUTING = splunk1, splunk2

I have tried props.conf and transforms.conf with targeting sourcetype, source and host.
TRANSFORMS-routing = azureauditlog_to_splunks

SOURCE_KEY = _MetaData:Index
REGEX = (?i)azure_audit
FORMAT = splunk1, splunk2

I have tried adding _TCP_ROUTING to to the inputs.conf, but it creates a new input.

_TCP_ROUTING = splunk1, splunk2

_TCP_ROUTING = splunk1, splunk2

I'm starting to run out of ideas. Anyone have any ideas?

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!