Installation

Which approch is easier to implement- installing Universal Forwarder(UF) or using the Splunk Add-on for Microsoft Cloud Services

Koko12345678
Explorer

from what I understood with Splunk Add-on for Microsoft Cloud Services, there are some configuration that I will have to perform, while with UF just an installation is required, which approach is preferred? and why?

thanks

Tags (1)
0 Karma

Koko12345678
Explorer

Thanks for the answer, but I still don't understand what is the benefit of using one over the other.
let's assume I used UF before it's more familiar to me, why should I'll want to work with new configuration of the add on?

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

In my opinion, the Splunk Add-on for Microsoft Cloud Services would be the better route. As with any Splunk Add-on, you will have the added value of things like field extractions. The Add-on also communicates via API, so I'm not even sure you could easily get at the same data. Also, you would still have to configure a Universal Forwarder to point it at the data sources you want to ingest, with the added task of extracting fields.

Here is a link to a blog post which helps with the configuration of the Add-on. I have had a few customers successfully utilize this post when configuring the Add-on.

https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html

0 Karma

Koko12345678
Explorer

Thanks for the answer, but I still don't understand what is the benefit of using one over the other.
let's assume I used UF before it's more familiar to me, why should I'll want to work with new configuration of the add on?

0 Karma
Get Updates on the Splunk Community!

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...