All Apps and Add-ons

what are the steps to configure Azure Diagnostics Splunk Add-on- Azure and splunk side?


I would like to know what are the specific steps and specific component I'll need to perform/create in order to configure/use Azure Diagnostics Splunk add-on. first from Azure side (e.g. VM with Azure Diagnostics extension ?storage account? Blob storage?), and then also from Splunk side.

I would appreciate if someone can provide a clear step by step to achieve this goal.


Tags (1)
0 Karma

Splunk Employee
Splunk Employee

Diagnostic logs in Azure is a very broad topic. Almost all services in Azure can expose diagnostic logs in 1 of 2 ways:

  1. Send logs to an Azure Storage Account. The Splunk Add-on for Microsoft Cloud Services can read the logs written to the account.
  2. Send logs to an Event Hub. The Azure Monitor Add-on for Splunk can read logs from the Event Hub(s).

In either of the above cases, it involves creating a diagnostic setting in Azure first. The diagnostic setting controls where logs are sent (storage and/or Event Hub). If you send logs to storage, check out this blog on getting the data into Splunk. If you send logs to an Event Hub, refer to these blogs for Azure setup and Splunk setup.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...