-
Notifications
You must be signed in to change notification settings - Fork 12
Source types for the Splunk Add on for Microsoft Azure
Jason Conger edited this page Jul 14, 2022
·
2 revisions
The Splunk Add-on for Microsoft Azure provides the index-time and search-time knowledge for Microsoft Azure data in the following formats:
| Data source | Default sourcetype(s) |
|---|---|
| Azure Active Directory Interactive Sign-ins | azure:aad:signin |
| Azure Active Directory Users | azure:aad:user |
| Azure Active Directory Groups | azure:aad:group |
| Azure Active Directory Audit | azure:aad:audit |
| Azure Active Directory Risk Detection | azure:aad:risk:detection |
| Azure Active Directory Devices | azure:aad:device |
| Metrics | azure:metrics |
| Security Center |
azure:securityCenter:alert azure:securityCenter:task
|
| Subscriptions | azure:subscriptions |
| Resource Groups | azure:resource:group |
| Virtual Networks |
azure:vnet azure:vnet:nic azure:vnet:nsg azure:vnet:ip:public
|
| Compute |
azure:compute:vm azure:compute:disk azure:compute:image azure:compute:snapshot
|
| Azure Billing and Consumption | azure:billing |
| Azure Reservation Recommendation | azure:reservation:recommendation |
| Azure Resource Graph | azure:resourcegraph |
| Azure Topology (automatic) | azure:topology |
| Azure Topology (manual) | azure:topology |
- Create an Azure AD App Registration
- Configure Permissions for an Azure AD App Registration
- Connect to your Azure Account with Splunk Add-on for Microsoft Azure
- Configure Azure Active Directory inputs
- Configure Azure Metrics inputs
- Configure Security Center Alerts & Tasks inputs
- Configure Azure Subscriptions inputs
- Configure Azure Resource Groups inputs
- Configure Azure Virtual Network inputs
- Configure Azure Compute inputs
- Configure Azure KQL Log Analytics inputs
- Configure Azure Billing and Consumption inputs
- Configure Azure Reservation Recommendation inputs
- Configure Azure Resource Graph inputs
- Configure Azure Topology inputs