Hello,
I'm trying to get a full coverage of data from Azure from metrics to risky sign-ins, so I try to figured out the best ways to collect events.
So far I work with both addons Cloud services & Microsoft Azure for my needs, based on this graphic to help myself https://jasonconger.com/splunk-azure-gdi/
But I'm facing the issue of subscriptions inputs settings for both addons, basically I understand that we have to set each subscriptions by ourselves, but it means we could miss some of them and especially the new created ones.
So I was thinking of a script API based which get all the subscriptions from Azure then push an inputs in Splunkcloud.
I've the feeling I'm not be the only one facing this problem, so I told me maybe someone might have found a better way to collect automatically all subscriptions.
Thanks in advance for your help ! 🙂
Ben
Same issue here.
looking into this, an collegae of my has created an separate python script to bypass this..
but now the app only collect the first subscription, looks like the app sees one and then stops.