The Azure Monitor Add-On for Splunk offers near real-time access to metric and log data from all of your Azure resources. Azure Monitor is Microsoft Azure’s built-in pipeline for searching, archiving, and routing your monitoring data, providing a single path for getting Azure data into Splunk. Simply configure your resources to send log and metric data into an event hub namespace, deploy the add-on, and configure the add on with your event hub namespace details and you are ready to go. The add-on currently supports these data types:
• Activity log, routed to event hub via a log profile
• Diagnostic logs, routed to event hub via diagnostic settings
• Metrics, routed to event hub via diagnostic settings