I am trying to monitor the Azure Storage Blobs and when we try logging into the application “Splunk Template for Microsoft Azure”, the dashboards for Storage (Usage-->Storage Accounts) displays the following error:
Does anybody know what we are doing wrong? Or alternately, if you have some specific documentation on permissions to check or API calls to run to see if data is being fetched would be helpful.
The exact error is: macro 'azure-metrics-storage' that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced
This macro didn’t exist at all. We tried creating the macro manually (to point to the index where storage data was written to and the mscs:storgage* sourcetype) and the dashboards just show null values.
For configuring the Storage Accounts, we followed the instructions as defined in the Microsoft Cloud Services Add-On. These are showing up properly in the Azure Storage Account configuration page.
For sourcetype mscs:storage:table we are seeing data only for below sources. Which seems to be missing any of the performance parameters as described in the dashboard. We have configured the Azure account with full permissions. So it should be returning all data.
Also, we saw this one error in the log files that was quite old but thought of sharing.
2018-07-02 04:39:01,574 +0000 log_level=ERROR, pid=60847, tid=Thread-14300, file=mscs_storage_table_data_collector.py, func_name=collect_data, code_line_no=62 | [stanza_name="ICP-AzureVMmetrics" account_name="microiapsaiap062707500" table_name="WADMetricsPT1MP10DV2S20180425"] Error occurred in collecting data Traceback (most recent call last): File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/mscs_storage_table_data_collector.py", line 58, in collect_data self._do_collect_data() File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/mscs_storage_table_data_collector.py", line 107, in _do_collect_data marker=page_link File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/azure/storage/table/tableservice.py", line 685, in query_entities resp = self._query_entities(*args, **kwargs) File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/azure/storage/table/tableservice.py", line 749, in _query
... View more