Getting Data In

Can we have one connect to Azure Commercial while the other connects to Azure Government event hubs?

HathMH
Path Finder

I have been asked to check with Splunk Support on whether we can run 2 different Splunk add-ins for "Splunk Add-on for Microsoft Cloud Services". Can we have one connect to Azure Commercial while the other connects to Azure Government event hubs? Or is this a case in which we would need 2 separate splunk servers to support that?

What else could we do? IE.  could we set it up on the heavy forwarder in the FTI subscription for Government for server 1 and use the existing server for commercial?

Labels (2)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't have experience with that particular TA, but I suspect you'll need two installations of it.  The easiest way to do that would be to install the TA on two different instances (2 HFs, for example).

If that's not an option then you can install the TA twice on the same instance, but one copy must have a different name and, most importantly, directory.  After installing the TA once, and before configuring it, copy the directory.  Be sure to edit the copy's default/app.conf file (yes, this is a case where you must edit a default file) to give the add-on a new name and directory.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...