Getting Data In

Does anyone have experience with using Data Manager for Azure and Splunk ES?

Junie
Loves-to-Learn

Hi there!  I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.

According to this link https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.

The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub).  Does DM contain that sourcetype needed for the ES stories?  Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?

 
 

 

 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Junie,

in a recent project, I preferred to use for Data ingestion some Add-Ons as:

Splunk Add-On for Microsoft Office 365 (https://splunkbase.splunk.com/app/4055)

Splunk Add-On for Microsoft Azure (https://splunkbase.splunk.com/app/3757)

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...