Getting Data In

Does anyone have experience with using Data Manager for Azure and Splunk ES?

Junie
Observer

Hi there!  I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.

According to this link https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.

The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub).  Does DM contain that sourcetype needed for the ES stories?  Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?

 
 

 

 

Labels (3)
0 Karma

gcusello
Esteemed Legend

Hi @Junie,

in a recent project, I preferred to use for Data ingestion some Add-Ons as:

Splunk Add-On for Microsoft Office 365 (https://splunkbase.splunk.com/app/4055)

Splunk Add-On for Microsoft Azure (https://splunkbase.splunk.com/app/3757)

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...