Getting Data In

Splunk report to fetch Azure orphaned disk details.

jatin
Explorer

Hello experts... I need help... I want to fetch Azure orphaned disk details... Can someone share splunk query for the same.

Labels (1)
0 Karma

jconger
Splunk Employee
Splunk Employee

Install the Splunk Add-on for Microsoft Cloud Services and configure the Azure Resource input.  Choose "Disk Data" as the resource type (see screenshot).

Then, you can use this search to find unattached (orphaned) disks:

index=main sourcetype="mscs:resource:disk" properties.diskState="unattached"

 

jconger_0-1708965359640.png

 

jatin
Explorer

I am new to Splunk so I don't know from where to start.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Where is the data you want to analysis? Have you already ingested it into Splunk?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some sample (anonymised) events

0 Karma

jatin
Explorer

I am new to Splunk so I don't know from where to start.

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...