Splunk Enterprise Security

Splunk Azure Deployment questions

adalbor
Builder

Hey All,

We are researching a potential Splunk deployment to the Azure cloud but had a few questions.

In the documentation listed on the blog "Announcing Splunk Enterprise in Microsoft Azure Marketplace" there is a diagram listing proposed topology. I notice that there is no mention of an ES server but an on-prem deployment would require one. Am I missing something here? Are there components that can't run in Azure that run in an on-prem setup? Do we lose any features by deploying there?

Thanks!
Andrew

0 Karma

woodcock
Esteemed Legend

Design the architecture that you would like (make sure to include firewall/port details), hand it off to your Azure team and they will create the servers for you. Treat the servers just like any other physical server. You can deploy any Splunk infrastructure, including ES, in Azure. We have done so.

0 Karma

jconger
Splunk Employee
Splunk Employee

The blog post mentioned centers around deploying Splunk Enterprise in Azure via the Azure Marketplace. Splunk Enterprise is a prerequisite for Enterprise Security. You can use the Azure Marketplace deployment to first deploy Splunk and then install Enterprise Security if you like.

There are some things to think about when deploying Splunk in Azure though. Things like managed disks, availability sets, instance size, etc. A white paper is available if you want to look at some of those details. This white paper details deploying Splunk in Azure manually instead of using the Azure Marketplace method.

0 Karma

adalbor
Builder

Thanks for the link, I have seen that one. Just without a mention of the ES I was quite curious.

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @adalbor

This looks like just a documentation issue. There is no problem with running ES in your Azure cloud.

Cheers, Chris

0 Karma

adalbor
Builder

Do you have or know of where I could find documentation detailing the entire deployment?

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @adalbor, There is really nothing that is unique to Azure. Use the marketplace to deploy the base Splunk images (or otherwise install base product yourself), and then just put ES on top following the normal, documented install process.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...