Splunk Cloud Platform

Microsoft Azure App for Splunk

monguyen
New Member

Hi, 

This photo includes the SPL search for the Microsoft Azure App for Splunk in the Billing Overview:

monguyen_0-1622052635019.pngmonguyen_0-1622052635019.png

This search no longer results in any events because the properties.pretaxCost and properties.usageQuantity fields no longer exist if I search:

index=item_prod_event_azure_90d OR index=cyber_prod_event_mscloud_1y sourcetype="azure:billing".

monguyen_1-1622053022658.pngmonguyen_1-1622053022658.png

 

Additionally, the fields seen in the following line also do not show up as fields any longer as well:

| dedup properties.usageStart properties.instanceId properties.meterDetails.meterSubCategory Cost properties.meterDetails.meterName Quantity

What can be done to view the billing information again?

Thanks so much! 

Labels (1)
0 Karma

monguyen
New Member

Good point. It does seem it could have been renamed.

Would it be possible to know what the fields have been renamed as to make sure I am pulling the correct information? Or who I can contact to check this? The ones that I am still unsure about are the properties.usageStart and properties.instanceId. I think it could be properties.date and properties.meterId, respectively, but it would be good for someone who changed the fields to confirm this. Thank you! 

0 Karma

dmacintosh_splu
Splunk Employee
Splunk Employee

The screenshot of the fields you shared contains the properties.cost and properties.quantity fields. Do the field values represent the data you want?

It is possible that Azure changed the name of the fields in the raw data.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...