Expanding the Azure Local Security Ecosystem with IBM QRadar and Splunk

Partners Jason Conger

Key takeaways

  1. Azure Local now integrates with Splunk and IBM QRadar, helping organizations monitor security signals within existing security operations platforms and workflows.
  2. These integrations support governments and regulated industries with security monitoring for controlled, sovereign, and disconnected environments while maintaining existing tools and processes.
  3. Splunk helps Azure Local customers gain operational visibility, accelerate investigations, and respond effectively while supporting security, sovereignty, and operational continuity.

Contributing author Ariel Netz, Partner Group Product Manager, Azure Edge Security

As regulatory obligations, resilience requirements, and the need for greater control over data and infrastructure continue to grow, we are seeing increasing interest in Azure Local from governments, critical infrastructure operators, defense organizations, and regulated industries looking to deploy cloud capabilities within customer-controlled environments.

These customers often have unique operational, compliance, and sovereignty requirements. Some operate in highly regulated environments with strict controls over data movement. Others require security operations capabilities that can integrate with existing investments and established operational processes.

Today, I am pleased to announce two new security monitoring integrations for Azure Local with IBM QRadar and Splunk. These integrations enable organizations to incorporate Azure Local security signals into their established security operations platforms, augmenting monitoring and investigation workflows while preserving the tools and processes their teams already rely on.

Building a Stronger Ecosystem for Azure Local

Security has always been a foundational principle of Azure Local. At the same time, we recognize that many customers operate environments where security operations investments and processes are already established and vetted. As Azure Local expands into new industries and sovereign private cloud scenarios, integration with these existing security operations investments becomes increasingly important.

By working closely with IBM QRadar and Splunk, we are expanding the partner ecosystem available to Azure Local customers enabling organizations to incorporate Azure Local security signals into their established security monitoring and investigation workflows. This approach gives organizations the flexibility to maintain continuity in their tools and processes while extending Azure Local capabilities into their existing security infrastructure.

Security Monitoring with IBM QRadar and Splunk

Azure Local has security built directly into the platform, with controls such as CIS- and DISA STIG-aligned security baselines, BitLocker encryption, Microsoft Defender Antivirus, and Attack Surface Reduction to help protect data and reduce risk. Beyond these built-in protections, Azure Local also generates security-relevant audit logs and alerts that integrate with partner security solutions for monitoring and investigation. (See: Manage syslog forwarding for Azure Local - Azure Local | Microsoft Learn)

Whether customers are modernizing existing infrastructure, deploying new sovereign private cloud environments, or extending established security operations processes to Azure Local deployments, these integrations help simplify adoption by building on technologies they already know and trust.

local-1.png

IBM QRadar

As organizations deploy into sovereign and disconnected environments, security operations must evolve to meet new demands. By collaborating with Microsoft, we're bringing QRadar's proven SIEM capabilities to Azure Local to deliver a powerful, integrated approach to security operations. This enables security teams to operate with comprehensive visibility and rapid response while preserving the control and isolation these environments require. - Cathal O'Donovan, Director Threat Management, IBM

Splunk

Organizations operating in sovereign and disconnected environments need security operations that can adapt to constrained conditions without sacrificing visibility or agility. By working with Microsoft, Splunk is bringing its data platform and analytics capabilities to Azure Local, enabling security teams to gain operational insight, accelerate investigations, and respond more effectively within highly controlled environments. Together, we’re enabling a more flexible and resilient approach to security operations for organizations where connectivity, sovereignty, and operational continuity are equally critical. - Jason Conger, Field CTO, Splunk a Cisco company

Looking Forward

Microsoft is actively engaging with partners across additional security categories, including endpoint detection and response, vulnerability management, and container security, to expand customer choice over time. These integrations reflect our ongoing investment in a broader security ecosystem for Azure Local and Sovereign Private Cloud deployments.

If you would like to learn more about Azure Local and these partner integrations, please contact your Microsoft account team.

Organizations interested in exploring partnership opportunities can reach out to aldopm@service.microsoft.com.

Related Articles

Using stats, eventstats & streamstats for Threat Hunting…Stat!
Security
5 Minute Read

Using stats, eventstats & streamstats for Threat Hunting…Stat!

The stats command is a crucial capability when you’re threat hunting. And so are two related commands: eventstats & streamstats. Get all the details, right here.
From Water to Wine: An Analysis of WINELOADER
Security
9 Minute Read

From Water to Wine: An Analysis of WINELOADER

In this blog post we'll look closely at the WINELOADER backdoor and how Splunk can be used to detect and respond to this threat.
The Final Shell: Introducing ShellSweepX
Security
8 Minute Read

The Final Shell: Introducing ShellSweepX

The Splunk Threat Research Team is excited to announce the final tool in the ShellSweep collection: ShellSweepX.