All Apps and Add-ons

Splunk add-on for Cloud services / Microsoft Azure : collect all subscriptions

Benjamin_D_B
Engager

Hello,

I'm trying to get a full coverage of data from Azure from metrics to risky sign-ins, so I try to figured out the best ways to collect events.
So far I work with both addons Cloud services & Microsoft Azure for my needs, based on this graphic to help myself https://jasonconger.com/splunk-azure-gdi/

But I'm facing the issue of subscriptions inputs settings for both addons, basically I understand that we have to set each subscriptions by ourselves, but it means we could miss some of them and especially the new created ones.

So I was thinking of a script API based which get all the subscriptions from Azure then push an inputs in Splunkcloud.
I've the feeling I'm not be the only one facing this problem, so I told me maybe someone might have found a better way to collect automatically all subscriptions. 

Thanks in advance for your help ! 🙂

Ben

Labels (1)

BenjaminAbben
SplunkTrust
SplunkTrust

Same issue here.

looking into this, an collegae of my has created an separate python script to bypass this..

but now the app only collect the first subscription, looks like the app sees one and then stops.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...