All Apps and Add-ons

Why is Azure Cloud Event-Hub Splunk Integration only showing one sourcetype?

avoelk
Communicator

Currently we're getting data from Azure Cloud which sends certain logs to a event hub our customer set up. then we pull the data from the eventhub just as stated in the documentation with the ms cloud services add-on. 

our problem is now that our customer wanted to see some dashboards filled out with the incoming data. normal request we thought so we installed the microsoft azure app for splunk. there we saw nothing. 

after further investigation we saw two things:

- the incoming data fields are all extracted but horribly named with long strings of names

- the sourcetype for all logs (around 7 different ones) is all something like xyz_eventhub which the app understandably doesn't know and can't use. 

 

so my question is how to fix the issue of only having one sourcetype even tho the props/transforms within the cloud services add-on should extract everything perfectly. we currently think about splitting the data with help of regex and props/transforms conf into the needed sourcetypes but I'm like "why the frick doesn't it work in the first place? I mean the vendor is microsoft and not a third party no-name"

 

glad for any ideas guys!

Labels (2)
Tags (1)
0 Karma

bahndg
Explorer

You may use Splunk Add-on for Microsoft Cloud Services https://splunkbase.splunk.com/app/3110/ in version 4.3.3+ (loops body.records now) and then use Microsoft Cloud Services Event Hub True Fashion Add-on for Splunk https://splunkbase.splunk.com/app/6508/

Your Azure Event hub message body nesting is completely gone now.

avoelk
Communicator

didn't see the answer, I'll try it out thanks a lot 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...