All Apps and Add-ons

Use Splunk Add-on for Microsoft Cloud Services with the German Cloud

thomashoppe
Engager

This Addon-on uses the Endpoint ...blob.core.windows.net for getting access to the Blob-Storage. The Microsoft German Cloud uses the Endpoint ...blob.core.cloudapi.de.
Is it possible to change the Endpoint the Add-on uses to access the Microsoft German Cloud?

ccornell_splunk
Splunk Employee
Splunk Employee

The file you edit depends on which parts of the MSCS Add-on you’re using, and the steps here assume you have set up your Azure-side with the correct region etc.:

If you are using the MSO365 part of the MSCS Add-on:

  • the o365 login endpoint URL AND the o365 management endpoint API URL is set in splunk_ta_ms_o365_server_ucc_system_setting.conf
  • the o365 management endpoint API URL is set in splunk_ta_ms_o365_api_settings.conf

Update the URLs to match the Azure Germany endpoints in those two files. Make sure that you update the API URL in both files before you restart to apply changes.

For the rest of the MSCS add-on functionality, these two files should be edited:

  • mscs_azure_accounts.conf.spec <- Azure Account Setting Schema (For ingesting Azure Audit Events)
  • mscs_storage_accounts.conf.spec <- Azure Storage Account Setting Schema

Find the variable account_class_type and set it to 3 (which should tell it to connect to the German endpoints).

Restart Splunk after changing these settings to apply the changes.

Note, if you’re using the MSCS Add-on for MSO365 data, you should migrate to the standalone MSO365 Add-on that was just recently released. It can live side-by-side with the current MSCS Add-on, but you have to disable the Office 365 modular input in the Splunk Add-on for Microsoft Cloud Service, see: http://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes

0 Karma

thomashoppe
Engager

When setting account_class_type to 3 the plugin tries to get data from chinacloudapi.net.
Setting it to 4 tells the plugin to use the German cloud.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...