What is the best way to import Log Analytics logs from Azure to Splunk ?
is there anyway to do it without using Even Hub ?
we are using Splunk Enterprise Version:7.3.4
we also have Heavy forwarder Splunk Enterprise Version:8.1
I have not seen a reliable way to pull in Log Analytics workspace data into splunk
https://splunkbase.splunk.com/app/4127/ - no longer functions on 8.2.x - developer no longer updating the add-on. This was a great add-on, worked for 2 years. now it's gone
https://splunkbase.splunk.com/app/4847/ - This will pull in the data, but it's a mess. There are no field extractions, and it pulls in data you do not need like table structure, and row structure. But it does not map them together or extract a single field. There is an option for CSV or JSON, both do the same thing, just brings in a pile of data.
Splunk has nothing for this.
The best way to collect data from azure is: the splunk add-on for microsoft clouds services and microsoft azure add-on for splunk
Anyway you can collect the log list below with a short description, you can collect many souces via rest or eventhub depend on the log type.
please start to see this guide
Also you can read this guide to urderstand all of kind of logs