Splunk Enterprise Security

Unexpected end of JSON input for Azure Monitor

elbrianle
New Member

Getting the following error message:

07-10-2019 13:02:18.411 +0000 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\etc\apps\TA-Azure_Monitor\bin\azure_activity_log.cmd"" Modular input azure_activity_log://Azure_Activity_Event_Hub Error getting event hub creds: SyntaxError: Unexpected end of JSON input

has anyone been able to resolve this issue?

0 Karma

marycordova
SplunkTrust
SplunkTrust

It's not a reliable TA, if you have the ability to do so, you might consider adopting a new method of log ingestion: https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html

@marycordova
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...