Getting Data In

Issues with Azure Loganlaytics KQL Grabber

KiranM
Loves-to-Learn

Hi Team,

We are trying to onboard the data from Azure Workspace, Below are the issues kindly address if u had gone through and tackled successfully.

1.  Upon creating the input, the input executes and sends data for a brief moment and then it stops. Since it is conf. on HF, once i renable the already enabled input again it sends some data and then thats it.

2. The latest version of app, doesnt work with JSON and CSV. Anyone tackled this. btw the json works but not usefull

 

So anyone solved these 2 any alternatives

Labels (3)
0 Karma

k_cummins
New Member

the addon you mentioned having multiple issues more than you faced. I suggest you to use another addon which is working perfectly for me. 

https://splunkbase.splunk.com/app/7130 

 

Give me a like if that solves yours

https://splunkbase.splunk.com/app/7130

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...