Hello experts... I need help... I want to fetch Azure orphaned disk details... Can someone share splunk query for the same.
Install the Splunk Add-on for Microsoft Cloud Services and configure the Azure Resource input. Choose "Disk Data" as the resource type (see screenshot).
Then, you can use this search to find unattached (orphaned) disks:
index=main sourcetype="mscs:resource:disk" properties.diskState="unattached"
I am new to Splunk so I don't know from where to start.
Where is the data you want to analysis? Have you already ingested it into Splunk?
Please share some sample (anonymised) events
I am new to Splunk so I don't know from where to start.