Splunk Dev

Implementing Splunk in Azure Functions

rallapallisagar
New Member

HI Team, we are trying to implement splunk in the azure functions .But we dont have any idea ,how to implement it. I  read we cant pass the custom logs from functions to Splunk.Can u pls helps us here with sample code and approach ?

Thanks,

R.Sagar

Labels (2)
0 Karma

Comandereric
Engager

Did you find a solution @rallapallisagar ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you open with some words what you are exactly trying to do?

0 Karma

Comandereric
Engager

Sure we have some Azure functions running with C# or Java code there for we have some custom log statements they go into the Eventhub and than to Splunk but Splunk have a problem with the format which comes from the Eventhub (nested jsons) eventhough the log messages are microsoft standard...

0 Karma

isoutamo
SplunkTrust
SplunkTrust

I have used eventhub with splunk without issues e.g. with AKS and other logs. Just use https://splunkbase.splunk.com/app/3110 this app to ingest those. 

0 Karma

aasabatini
Motivator

Hi @rallapallisagar 

Ithink the best way to start to collect azure event logs is read these two articles

https://www.splunk.com/en_us/blog/tips-and-tricks/getting-microsoft-azure-data-into-splunk.html

https://www.splunk.com/en_us/blog/platform/splunking-azure-event-hubs.html

However, if these articles aren't enough, please don't hesitate to ask

Regards

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...