All Apps and Add-ons

Why is Microsoft Azure App for Splunk not showing any data?

steveirogers
Communicator

We are running in Splunk Cloud and have configured the "Splunk Add-On for Microsoft Cloud Services" based on the provided configuration documentation.

I am trying to use the Microsoft Azure App for Splunk to view Azure data (which I presumed would be pulled in by the "Splunk Add-On for Microsoft Cloud Services", but the Microsoft Azure App for Splunk shows no data at all.

I have verified the Add-on configuration, but still not seeing any data?  Does anyone have this app working and displaying results?

Best regards,
Steve Rogers

 

 

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

Kindly check the splunkd.log and Add-on's logs to see if any errors you are encountering.

View solution in original post

AllenZhang
Explorer

How many inputs have you configured on the add-on?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Kindly check the splunkd.log and Add-on's logs to see if any errors you are encountering.

steveirogers
Communicator

Hello Vatsal,

Thanks for the response.  I don't see any errors in the Splunkd log.  I will reach out to Splunk support for assistance.

 

Best regards.

0 Karma

avoelk
Communicator

Hello,

 

I'm facing the same issue. do you use event hub before the data goes to splunk? at least that's what was written in many documentations that this is necessary. 

anyways, the problem results in the use of event hub. since event hub is only giving one sourcetype for all the data that it is processing, something like "xyz_eventhub" so the azure app can't handle this since it is looking for sourcetypes for health report, signins etc. 

as far as I understand I have to split all the incoming data in props/transforms according to specific markers, such as category of the event and then regex it to work. 

maybe that's the way you have to go too? if there is another way, I'm all ears btw. 

 

cheers,

0 Karma

klaxdal
Contributor

Anyone get this fixed ? I have the same issues 

0 Karma

alexsoul
New Member

hi, we are facing same issue - no errors, everything looks clean, all config looks ok and still no logs are being ingested. I wonder if that even hub is really necessary for this add-on to work? I am really looking to pull data via API... and for now without event hub. Anyone has any ideas where do we start digging? Could that be anything at Azure side that we are missing? Maybe permissions or something?  

0 Karma

rmeena21
Observer

@avoelkany leads on the mscs:azure:eventhub single sourcetype data feed?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...