Getting Data In

Does anyone have experience with using Data Manager for Azure and Splunk ES?

Junie
Observer

Hi there!  I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.

According to this link https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.

The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub).  Does DM contain that sourcetype needed for the ES stories?  Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?

 
 

 

 

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Junie,

in a recent project, I preferred to use for Data ingestion some Add-Ons as:

Splunk Add-On for Microsoft Office 365 (https://splunkbase.splunk.com/app/4055)

Splunk Add-On for Microsoft Azure (https://splunkbase.splunk.com/app/3757)

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...