Getting Data In

Splunk report to fetch Azure orphaned disk details.

jatin
Explorer

Hello experts... I need help... I want to fetch Azure orphaned disk details... Can someone share splunk query for the same.

Labels (1)
0 Karma

jconger
Splunk Employee
Splunk Employee

Install the Splunk Add-on for Microsoft Cloud Services and configure the Azure Resource input.  Choose "Disk Data" as the resource type (see screenshot).

Then, you can use this search to find unattached (orphaned) disks:

index=main sourcetype="mscs:resource:disk" properties.diskState="unattached"

 

jconger_0-1708965359640.png

 

jatin
Explorer

I am new to Splunk so I don't know from where to start.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Where is the data you want to analysis? Have you already ingested it into Splunk?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some sample (anonymised) events

0 Karma

jatin
Explorer

I am new to Splunk so I don't know from where to start.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...