Getting Data In

Azure connection concern

roopeshetty
Path Finder

Hi

I know there are many splunk add on's available to collect azure monitor metrics which collects the logs using app id, client id, directory and secret key.  My question is how these add on's actually authenticate and pulls these azure metrics, as azure these metrics can only be retrieved using bearer tokens. If we create bearer token in azure monitor its valid for only 24 hours. 

Actually we need to create some custom add ons to pull azure metrics, but unable to crack how to authenticate. Can some one please guide us.

 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @roopeshetty,

we're ingesting logs from Azure using two Add-Ons:

Following the above links you can find a detailed procedure to configure Azure to send logs to Splunk.

We configured the accounts on Azure to take logs and they are working from september without changing them, but I'm not sure that they are the same, for this reason I hint to follow the documentation.

If you're speking of something different, search in Splunk Baseline if there's some Add-On that can help you.

Only one attention, not all the logs and report are free in Azure, there's something that requires a dedicated license in Azure, so check this.

It's un'useful to ask help to Microsoft because they don't answer to any question if you say "splunk".

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...