We are currently tasked at having Splunk monitor an AKS in Azure, and comparing two solutions:
- Installing Splunk Connect for Kubernetes in AKS, as per this thread: We are thinking of moving to Azure Kontainer Servi... - Splunk Community
- Another pattern that was done before is to enable Azure Monitor, which in turn ships logs to Event Hub and eventually consumed by Splunk via the Splunk Addon for Microsoft Cloud Services.
How does the two solutions compare and what is the preferred solution?