All Apps and Add-ons

Use Splunk Add-on for Microsoft Cloud Services with the German Cloud

thomashoppe
Engager

This Addon-on uses the Endpoint ...blob.core.windows.net for getting access to the Blob-Storage. The Microsoft German Cloud uses the Endpoint ...blob.core.cloudapi.de.
Is it possible to change the Endpoint the Add-on uses to access the Microsoft German Cloud?

ccornell_splunk
Splunk Employee
Splunk Employee

The file you edit depends on which parts of the MSCS Add-on you’re using, and the steps here assume you have set up your Azure-side with the correct region etc.:

If you are using the MSO365 part of the MSCS Add-on:

  • the o365 login endpoint URL AND the o365 management endpoint API URL is set in splunk_ta_ms_o365_server_ucc_system_setting.conf
  • the o365 management endpoint API URL is set in splunk_ta_ms_o365_api_settings.conf

Update the URLs to match the Azure Germany endpoints in those two files. Make sure that you update the API URL in both files before you restart to apply changes.

For the rest of the MSCS add-on functionality, these two files should be edited:

  • mscs_azure_accounts.conf.spec <- Azure Account Setting Schema (For ingesting Azure Audit Events)
  • mscs_storage_accounts.conf.spec <- Azure Storage Account Setting Schema

Find the variable account_class_type and set it to 3 (which should tell it to connect to the German endpoints).

Restart Splunk after changing these settings to apply the changes.

Note, if you’re using the MSCS Add-on for MSO365 data, you should migrate to the standalone MSO365 Add-on that was just recently released. It can live side-by-side with the current MSCS Add-on, but you have to disable the Office 365 modular input in the Splunk Add-on for Microsoft Cloud Service, see: http://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes

0 Karma

thomashoppe
Engager

When setting account_class_type to 3 the plugin tries to get data from chinacloudapi.net.
Setting it to 4 tells the plugin to use the German cloud.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...