Getting Data In

Does anyone have experience with using Data Manager for Azure and Splunk ES?

Junie
Loves-to-Learn

Hi there!  I'm wondering if anyone out there has experience with using Data Manager for Azure onboarding.

According to this link https://docs.splunk.com/Documentation/DM/1.7.0/User/GDIOverview#Getting_data_in_for_Microsoft_Azure it shows that there are only TWO supported sourcetypes, azure:monitor:aad and azure:monitor:activity.

The searches for Enterprise Security Analytic Stories for Azure uses a macro named azuread which is looking for a specific sourcetype (mscs:azure:eventhub).  Does DM contain that sourcetype needed for the ES stories?  Or will I still need to be ingesting eventhub via the Splunk Add-on for Microsoft Cloud Services TA?

 
 

 

 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Junie,

in a recent project, I preferred to use for Data ingestion some Add-Ons as:

Splunk Add-On for Microsoft Office 365 (https://splunkbase.splunk.com/app/4055)

Splunk Add-On for Microsoft Azure (https://splunkbase.splunk.com/app/3757)

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...