Installation

Which approch is easier to implement- installing Universal Forwarder(UF) or using the Splunk Add-on for Microsoft Cloud Services

Koko12345678
Explorer

from what I understood with Splunk Add-on for Microsoft Cloud Services, there are some configuration that I will have to perform, while with UF just an installation is required, which approach is preferred? and why?

thanks

Tags (1)
0 Karma

Koko12345678
Explorer

Thanks for the answer, but I still don't understand what is the benefit of using one over the other.
let's assume I used UF before it's more familiar to me, why should I'll want to work with new configuration of the add on?

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

In my opinion, the Splunk Add-on for Microsoft Cloud Services would be the better route. As with any Splunk Add-on, you will have the added value of things like field extractions. The Add-on also communicates via API, so I'm not even sure you could easily get at the same data. Also, you would still have to configure a Universal Forwarder to point it at the data sources you want to ingest, with the added task of extracting fields.

Here is a link to a blog post which helps with the configuration of the Add-on. I have had a few customers successfully utilize this post when configuring the Add-on.

https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html

0 Karma

Koko12345678
Explorer

Thanks for the answer, but I still don't understand what is the benefit of using one over the other.
let's assume I used UF before it's more familiar to me, why should I'll want to work with new configuration of the add on?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Note: This post outlines a proposed architecture and serves as an interest check. If we secure commitments ...