Data Manager Enables Microsoft Azure Data Onboarding!

On the heels of several exciting developments about Splunk Cloud Platform announced at .conf22, I am excited to share today that Data Manager now supports onboarding of Microsoft Azure data sources, effective immediately. This means you can use the same Data Manager application in your Splunk Cloud Platform to onboard critical Azure data sources — including Azure Active Directory logs and Azure Activity logs — to generate actionable insights in Splunk related to sign-in patterns, critical alerts related to Azure resource modifications, system activities related to users, groups, and applications, and gain visibility into the health status of critical resources.

The availability of Azure data onboarding is in addition to AWS data onboarding that was enabled earlier this year. Data Manager ships as a built-in application in Splunk Cloud Platform and is available today to all Splunk Cloud Platform customers who have chosen AWS as their provider and are on Victoria and Classic (except GovCloud US-West and US-East) experiences.

By providing minimum information about your cloud environments in Data Manager’s rich user interface, you can easily onboard data from both AWS and Azure, and manage your configured data inputs from one central location, irrespective of which cloud provider’s data you are bringing in.

“The thing that impressed me the most about Data Manager was it took less than 30 min to set up what before took several hours of multiple sessions with our cloud team over the course of several weeks. Being able to import, action, and monitor your data that fast is impressive.” - Joseph Schooler, Data Scientist, Cirrus Logic

Key Capabilities and Use Cases Enabled Through this Launch

All prerequisites and relevant Azure setup information is easily accessible and consumable through the Data Manager UI with in-context documentation along with a flow diagram of the setup (shown above). You can even choose to send data from each Azure service to a different Splunk index. We also auto-generate the Azure Resource Manager (ARM) templates for you with clear steps to run them in your Azure environment through PowerShell or CLI, providing transparency for you and your Azure admin to review the setup at any time. Once set up, your data input configuration is easy to monitor in Splunk through a single pane of glass to help ensure your Azure data flows into Splunk smoothly.

Onboarding Azure Data Sources in Data Manager

Now lets see Data Manager in action, where you’ll learn how to onboard Azure Active Directory logs in Data Manager, how Azure resources such as Event Hubs, Azure Storage, and Azure functions are set up in your Azure environment using the ARM template from Data Manager, and how the data starts flowing immediately after the Azure data input is successfully created in Data Manager.

YouTube video player

That’s how simple it is to onboard Azure Active Directory logs in Splunk using Data Manager! In case you are also interested in onboarding Azure Activity logs, all you have to do is create a new data input in Data Manager and follow the configuration steps in the Data Manager UI. For more information, please see onboarding Azure data in Data Manager.

Try out this new capability today to help you get to the cloud faster while making your data work for you.

Have feedback? Share your thoughts with us and other uses on the Splunk Community.

----------------------------------------------------
Thanks!
Sulay Shah

Related Articles

Developing the Splunk App for Anomaly Detection
Platform
13 Minute Read

Developing the Splunk App for Anomaly Detection

A technical overview of the Splunk App for Anomaly Detection, which uses machine learning to automatically configure anomaly detection jobs on time series data.
Enhancements To Ingest Actions Improve Usability and Expand Searchability Wherever Your Data Lives
Platform
4 Minute Read

Enhancements To Ingest Actions Improve Usability and Expand Searchability Wherever Your Data Lives

Along with the respective Splunk Enterprise version 9.1.0 and Splunk Cloud Version 9.0.2305 releases, Ingest Actions has launched a new set of features and capabilities that improve its usability and expand on configurability of data routed by Ingest Actions to S3.
Flatten the SPL Learning Curve: Introducing Splunk AI Assistant for SPL
Platform
3 Minute Read

Flatten the SPL Learning Curve: Introducing Splunk AI Assistant for SPL

At .conf23, we announced the preview release of Splunk AI Assistant - Splunk's first offering powered by generative AI.
Splunk Edge Processor Enhancements Offer Greater Data Access and Improve Data Management
Platform
1 Minute Read

Splunk Edge Processor Enhancements Offer Greater Data Access and Improve Data Management

On the heels of an exciting GA in March and the April announcement of its regional expansion, we are excited to share the latest updates to Splunk Edge Processor that will make it even easier for customers to have more flexibility and control over just the data you want, nothing more nothing less.
Fastest Time-to-Value Anomaly Detection in Splunk: The Splunk App for Anomaly Detection 1.1.0
Platform
3 Minute Read

Fastest Time-to-Value Anomaly Detection in Splunk: The Splunk App for Anomaly Detection 1.1.0

Splunk App for Anomaly Detection simplifies ML, making anomaly detection easy. It streamlines tasks, enabling ML integration in everyday workflows. Just load data, select the field, and click "Detect Anomalies."
Swimming in Sensors and Drowning in Data: The Role of Splunk Partners in Delivering Splunk Edge Hub
Platform
3 Minute Read

Swimming in Sensors and Drowning in Data: The Role of Splunk Partners in Delivering Splunk Edge Hub

With the proliferation of edge computing and the release of Splunk Edge Hub, partners have additional functionality to accelerate the detection, investigation and response of threats and issues that will inevitably occur in physical and industrial environments.
Introducing New Deep Learning NLP Assistants for DSDL
Platform
6 Minute Read

Introducing New Deep Learning NLP Assistants for DSDL

The Splunk App for Data Science and Deep Learning (DSDL) now has two new assistant features for Natural Language Processing. DSDL has been offering basic natural language processing (NLP) capabilities using the spaCy library.
Announcing the General Availability of Cloud Monitoring Console’s Maintenance Dashboard
Platform
3 Minute Read

Announcing the General Availability of Cloud Monitoring Console’s Maintenance Dashboard

The new Maintenance Dashboard in the Cloud Monitoring Console app aims to assist Splunk Cloud Platform admins in effectively managing maintenance tasks and staying informed about Splunk-initiated maintenance for improved operational efficiency.
What is Splunk Virtual Compute (SVC)?
Platform
7 Minute Read

What is Splunk Virtual Compute (SVC)?

Learn about what SVCs are, how they fit in with workload pricing, and how to size, monitor, and manage workload to get the most out of Splunk.