I have tried creating inputs for both:
Azure Audit
Azure Resource
I also created the required Azure App Account that is referenced when creating the input. The Azure App Account was created with the required Client ID, Key(Client Secret), and Tenant ID
I have also created Data Inputs by selecting my specific Splunk Add-on such as Microsoft Cloudservice Azure Audit which can be found by going to Setttings > Data Inputs > Splunk Add-on for Microsoft Cloudservice Azure Audit and nothing has worked to get data into my index.
According to the Splunk docs Azure Audit is to be used when trying to pull data from Azure applications that use Azure Application Insights.
Can anyone tell me if they have this working and if so what was configured? All of my Splunk configurations were done through the GUI.
... View more