Getting Data In

Moving files from Azure Blob Storage to Splunk Cloud

New Member


Are there any plugins or up to date tutorials on how to move files from Azure blob storage to Splunk Cloud? Are there any best practices recommended on how to approach the forwarding from Azure to Splunk Cloud?

I have seen the HTTP Collector and I believe it could possibly be a solution in conjunction with Event Hubs and/or Azure Functions, but I'm not sure if that would be correct and the most recommended.

Any examples would be much appreciated.

Kind regards,

Tags (3)
0 Karma

Re: Moving files from Azure Blob Storage to Splunk Cloud

Splunk Employee
Splunk Employee

You can use a heavy forwarder with the Splunk Add-on for Microsoft Cloud Services to read data from the blob and forward on to Splunk Cloud. This heavy forwarder could live in Azure, on your premises, or anywhere that has access to the internet. With Splunk Cloud, you could get an Input Data Manager (IDM) provisioned that could run the add-on as well.

Anything specific you are looking to get from the Azure blob? Is it diagnostic data/logs from other Azure resources? If so, there may be a better/easier way to do it versus using blobs.