There are a lot of services in Microsoft Azure, and a lot of those services are producing machine data. Hal Rottenberg wrote a post covering several of these services and some ways to integrate Splunk with Microsoft Azure. We recently released a new cross-platform Azure add-on that consumes data for some IaaS and PaaS services. In this blog post, I will detail what we are collecting, how to use the data, and what is coming next for the add-on.
The add-on ships with three modular inputs:
These modular inputs rely on diagnostic data written to an Azure Storage account. For more information about enabling diagnostic data for your Virtual Machines and Azure Websites, refer to this article.
There are several prebuilt panels included in the add-on to get you started quickly:
Windows Events
Performance
Azure Website
General
[UPDATE] Azure Audit logs are now part of the Splunk Add-on for Microsoft Azure.
The next integration slated to roll into this add-on is Azure audit data. This modular input will pull data from the Azure Insights Events API. The idea here is to be able to tell who did what and when.
In addition to collecting data from Microsoft Azure, it is possible to quickly spin up Splunk workloads in Azure. The easiest way to do this is by using the Azure Marketplace. For more information on this, read Roy Arsan’s article about Splunk in the Azure Marketplace.
Downlaod the Azure Add-on on Splunkbase
The world’s leading organizations rely on Splunk, a Cisco company, to continuously strengthen digital resilience with our unified security and observability platform, powered by industry-leading AI.
Our customers trust Splunk’s award-winning security and observability solutions to secure and improve the reliability of their complex digital environments, at any scale.