Getting Data In

Does anyone have experience with using Data Manager for Azure and Splunk ES?

Junie
Observer

Hi there!  I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.

According to this link https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.

The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub).  Does DM contain that sourcetype needed for the ES stories?  Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?

 
 

 

 

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Junie,

in a recent project, I preferred to use for Data ingestion some Add-Ons as:

Splunk Add-On for Microsoft Office 365 (https://splunkbase.splunk.com/app/4055)

Splunk Add-On for Microsoft Azure (https://splunkbase.splunk.com/app/3757)

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...