Ithink the best way to start to collect azure event logs is read these two articles
https://www.splunk.com/en_us/blog/tips-and-tricks/getting-microsoft-azure-data-into-splunk.html
https://www.splunk.com/en_us/blog/platform/splunking-azure-event-hubs.html
However, if these articles aren't enough, please don't hesitate to ask
Regards
Alessandro