Hi Gcusello, thanks for the input. i have VM logs pushed to blob storage, from there splunk access the logs. these logs are pushed every 15mins to Splunk, there is no data/metrics to account for this. for example, if the VM is deleted( this is a problem), i am looking to have a real time query/dashboard that show me a summary of live VM`s, the last log that was push before the VM was destroyed as i believe the dashboard should provide me metrics so i can analyse further,. Again can this process be automated, rather than manually running this query to get the dashboard displayed.
... View more