- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does anyone have experience with using Data Manager for Azure and Splunk ES?
Hi there! I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.
According to this link https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.
The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub). Does DM contain that sourcetype needed for the ES stories? Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Junie,
in a recent project, I preferred to use for Data ingestion some Add-Ons as:
Splunk Add-On for Microsoft Office 365 (https://splunkbase.splunk.com/app/4055)
Splunk Add-On for Microsoft Azure (https://splunkbase.splunk.com/app/3757)
Ciao.
Giuseppe
