One key difference is Eventhub ingestion. Microsoft Azure Add on for Splunk (now deprecated) -> ingests Eventhubs through old ClientSecret String Splunk Add-on for Microsoft Cloud Services -> ingests Eventhubs through modern Azure-AD app with Reader rights into eventhub
... View more