What am I missing here?
So we have the MSCS TA installed and the data from an Azure Storage Account is been ingested into Splunk as `mscs:vm:metrics` sourcetype. The `CounterName` field has several metric names present so that side looks good.
I have looked high and low for preconfigured searches and dashboards for said sourcetype but to no avail.
There is no Content Pack (yet?) in the ITSI app for Azure and SIM is cloud only. We are running on-prem only.
So: one cannot do any dashboards for Azure VM metrics without SIM and paid for ITSI app?