Splunk and Microsoft Azure – Intro and Resource Roundup

Update Mar 15th, 2016: Jason Conger has announced the beta of the Azure Add-On for Splunk!

Update Feb 18th, 2016: Roy Arsan has announced the launch of Splunk Enterprise in the Azure Marketplace!

Note: the below article was written back in Dec 2014, but still gets a ton of hits and questions. Be sure to check out the Azure tag here on Splunk Blogs for the latest news.

We are often asked by customers about how Splunk can integrate with, or run in Microsoft’s Azure cloud platform. There’s actually a fair bit of information about this broad topic on splunk.com and elsewhere, but it can be a bit hard to find. This post will serve as an introduction to a few Azure terms, and a round-up of available resources. Subsequent posts will cover some of these concepts in more detail–just look for the posts tagged “Azure”! You might also want to check out the Microsoft tag for other resources related to Splunk and overall Microsoft ecosystem.

First, let’s be clear: this is a HUGE topic. Cloud platforms are very complex these days, and Azure is no exception. If you walk up to a Splunker and ask, “can Splunk run in Azure?”, or “can Splunk integrate with Azure?”, well the answer is “yes“. If you actually want a helpful answer, be prepared for us to ask for just a bit more information!

Second, let’s set a baseline of understanding with some simple definitions and statements for those new to Azure:

Blob storage stores file data. A blob can be any type of text or binary data, such as a document, media file, or application installer. Table storage stores structured datasets. Table storage is a NoSQL key-attribute data store, which allows for rapid development and fast access to large quantities of data. Queue storage provides reliable messaging for workflow processing and for communication between components of cloud services. File storage (Preview) offers shared storage for legacy applications using the standard SMB 2.1 protocol.

Ok, enough preamble, here’s what I’ve found for resources related to Splunk + Azure that should get you started down that path:

Splunk Apps

Apps like these are VERY important. The topic of getting data out of Azure and into Splunk deserves its own blog post, if not several. Why? The answer is simple: Splunk doesn’t natively know how to read data from a blob container, an Azure table. or an Azure queue. But no worries, Splunk is a platform!

Code

Azure Integrations

Not many things to mention yet, hopefully this list will grow!

FAQ

Presentations

Searching on the .conf website, I was able to find five slide decks! You can browse all of the past sessions by going to the 2013 sessions or 2014 sessions pages. Video recordings are available for most .conf2014 sessions.

Edits:

http://conf.splunk.com/sessions/2014/conf2014_SWarrington_Microsoft_Business_Analytics.mp4

Podcast: Play in new window | Download

----------------------------------------------------
Thanks!
Hal Rottenberg

No results