Hi,
I am setting this up for the first time and have questions regarding how to configure it. I have function apps that are using app insights and a shared log analytics workspace. Do I need to configure a diagnostic setting on the individual function app to use the event hub to stream the logs to Splunk or do I setup a diagnostic setting on the log analytics workspace that will send all the logs it receives to Splunk? Additionally, if there is any documentation on how to configure this it would be very much appreciated.
Thanks!
Ethan