All Apps and Add-ons

Splunk add-on for Microsoft Cloud Service v3.0.0 - multi Azure account question

evandervecht
New Member

Hi,

Currently I have an issue with the Splunk add-on for Microsoft Cloud Services.

I have 4 Azure accounts which I want to collect Audit logs from and I have configured them in mscs_azure_accounts.conf

[Azure Test]
account_class_type = 1
client_id = client_id
client_secret = clientSecret
tenant_id = tenant_id

[Azure Acceptance]
account_class_type = 1
client_id = client_id
client_secret = client_secret
tenant_id = tenant_id

[Azure Production]
account_class_type = 1
client_id = client_id
client_secret = client_secret
tenant_id = tenant_id

[Azure Services]
account_class_type = 1
client_id = client_id
client_secret = client_secret
tenant_id = tenant_id

We have 1 Heavy forwarder in our Services environment which collects the information.

What I noticed is that the addon only collects information from the [Azure Services] environment, which is the latest entry in the conf file as shown above.
Each account has been tested seperatly so I know the accounts are working fine.

I haven't found a post saying or an entry in the documentation pointing out that you can only have 1 account in the accounts config.

Did anyone else has seen this and if so, how did you solve this ?

0 Karma

evandervecht
New Member

I found the issue. In the mscs_azure_audit_inputs.conf file for each section it had the same section name

[Audit Logs] 
account=Azure Test

[Audit Logs] 
account=Azure Acceptance

[Audit Logs] 
account=Azure Production

[Audit Logs] 
account=Azure Services

Changing this to

[Audit Logs Test] 
account=Azure Test

[Audit Logs Acceptance] 
account=Azure Acceptance

[Audit Logs Production] 
account=Azure Production

[Audit Logs Services] 
account=Azure Services

Solved the issue

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...