Splunk Enterprise Security

Unexpected end of JSON input for Azure Monitor

New Member

Getting the following error message:

07-10-2019 13:02:18.411 +0000 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\etc\apps\TA-Azure_Monitor\bin\azure_activity_log.cmd"" Modular input azure_activity_log://Azure_Activity_Event_Hub Error getting event hub creds: SyntaxError: Unexpected end of JSON input

has anyone been able to resolve this issue?

0 Karma


It's not a reliable TA, if you have the ability to do so, you might consider adopting a new method of log ingestion: https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!