All Apps and Add-ons

Splunk add-on for Cloud services / Microsoft Azure : collect all subscriptions

Benjamin_D_B
Engager

Hello,

I'm trying to get a full coverage of data from Azure from metrics to risky sign-ins, so I try to figured out the best ways to collect events.
So far I work with both addons Cloud services & Microsoft Azure for my needs, based on this graphic to help myself https://jasonconger.com/splunk-azure-gdi/

But I'm facing the issue of subscriptions inputs settings for both addons, basically I understand that we have to set each subscriptions by ourselves, but it means we could miss some of them and especially the new created ones.

So I was thinking of a script API based which get all the subscriptions from Azure then push an inputs in Splunkcloud.
I've the feeling I'm not be the only one facing this problem, so I told me maybe someone might have found a better way to collect automatically all subscriptions. 

Thanks in advance for your help ! 🙂

Ben

Labels (1)

BenjaminAbben
SplunkTrust
SplunkTrust

Same issue here.

looking into this, an collegae of my has created an separate python script to bypass this..

but now the app only collect the first subscription, looks like the app sees one and then stops.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...