Hi there! I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.
According to this link https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.
The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub). Does DM contain that sourcetype needed for the ES stories? Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?
Hi @Junie,
in a recent project, I preferred to use for Data ingestion some Add-Ons as:
Splunk Add-On for Microsoft Office 365 (https://splunkbase.splunk.com/app/4055)
Splunk Add-On for Microsoft Azure (https://splunkbase.splunk.com/app/3757)
Ciao.
Giuseppe