Getting Data In

Can we have one connect to Azure Commercial while the other connects to Azure Government event hubs?

HathMH
Path Finder

I have been asked to check with Splunk Support on whether we can run 2 different Splunk add-ins for "Splunk Add-on for Microsoft Cloud Services". Can we have one connect to Azure Commercial while the other connects to Azure Government event hubs? Or is this a case in which we would need 2 separate splunk servers to support that?

What else could we do? IE.  could we set it up on the heavy forwarder in the FTI subscription for Government for server 1 and use the existing server for commercial?

Labels (2)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't have experience with that particular TA, but I suspect you'll need two installations of it.  The easiest way to do that would be to install the TA on two different instances (2 HFs, for example).

If that's not an option then you can install the TA twice on the same instance, but one copy must have a different name and, most importantly, directory.  After installing the TA once, and before configuring it, copy the directory.  Be sure to edit the copy's default/app.conf file (yes, this is a case where you must edit a default file) to give the add-on a new name and directory.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...