Splunk Enterprise

Microsoft Azure Add-on for Splunk keeps stopping/delaying

_joe
Contributor

I am just wondering if others are running into this same issues. I find that some of my sourcetypes mysteriously just stop for a while. They start up again eventually, but we don't really want huge delays in our data.

 

The azure:aad:signin sourcetype seems to give me the most trouble. Sometimes it may stop for a few hours - but then will immediately provide data if I bounce the input. During this time, I am not even getting debug logs for "source=*ta_ms_aad_MS_AAD_signins.log."

 

Most recently when I had an issue I noticed a "HTTPError: 504 Server Error: Gateway Timeout for url" for my aad_risk_detection ingest, so I do suspect network issues play a part in the problem. However, that really doesn't address what is happening to the retries...

 

Microsoft Azure Add-on for Splunk 3.1.1
Splunk Enterprise 8.0.5

Labels (1)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...