Getting Data In

How to index data from Azure Blob Storage in Splunk?

evconrad
New Member

Hello,

It seems like a basic question, but I would like to pull data that resides in files in Azure Blob Storage and index it in Splunk. This would be an automated process, once files arrive in Azure, they would at some point be uploaded into Splunk. Of course, I would have to make Splunk understand the formats, but is there a 'best practice' or 'accepted' way to do this? It appears that the Azure Splunk adds in process specific log files from Azure, not custom content that I want to have indexed.

Thanks for any advice. I'm new to Splunk and trying to get wrapped around the right way to do things.

0 Karma

larmesto
Path Finder

This might be helpful for anyone visiting; I have started working on an addon for Azure Event Hubs for Splunk, feel free to use it!
https://splunkbase.splunk.com/app/4343/

regards,

0 Karma

jawaharas
Motivator

Is this add-on works in Splunk 8.0.2.1?

0 Karma

arunkabrahamdnb
New Member

You can install the Splunk add on for Azure. Then configure the storage account. Configured the input as blob by specify the interval for pulling data from Blob storage. You will get the data from blob indexed in Splunk

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...