Data Manager Enables Microsoft Azure Data Onboarding!

On the heels of several exciting developments about Splunk Cloud Platform announced at .conf22, I am excited to share today that Data Manager now supports onboarding of Microsoft Azure data sources, effective immediately. This means you can use the same Data Manager application in your Splunk Cloud Platform to onboard critical Azure data sources — including Azure Active Directory logs and Azure Activity logs — to generate actionable insights in Splunk related to sign-in patterns, critical alerts related to Azure resource modifications, system activities related to users, groups, and applications, and gain visibility into the health status of critical resources.

The availability of Azure data onboarding is in addition to AWS data onboarding that was enabled earlier this year. Data Manager ships as a built-in application in Splunk Cloud Platform and is available today to all Splunk Cloud Platform customers who have chosen AWS as their provider and are on Victoria and Classic (except GovCloud US-West and US-East) experiences.

By providing minimum information about your cloud environments in Data Manager’s rich user interface, you can easily onboard data from both AWS and Azure, and manage your configured data inputs from one central location, irrespective of which cloud provider’s data you are bringing in.

“The thing that impressed me the most about Data Manager was it took less than 30 min to set up what before took several hours of multiple sessions with our cloud team over the course of several weeks. Being able to import, action, and monitor your data that fast is impressive.” - Joseph Schooler, Data Scientist, Cirrus Logic

Key Capabilities and Use Cases Enabled Through this Launch

All prerequisites and relevant Azure setup information is easily accessible and consumable through the Data Manager UI with in-context documentation along with a flow diagram of the setup (shown above). You can even choose to send data from each Azure service to a different Splunk index. We also auto-generate the Azure Resource Manager (ARM) templates for you with clear steps to run them in your Azure environment through PowerShell or CLI, providing transparency for you and your Azure admin to review the setup at any time. Once set up, your data input configuration is easy to monitor in Splunk through a single pane of glass to help ensure your Azure data flows into Splunk smoothly.

Onboarding Azure Data Sources in Data Manager

Now lets see Data Manager in action, where you’ll learn how to onboard Azure Active Directory logs in Data Manager, how Azure resources such as Event Hubs, Azure Storage, and Azure functions are set up in your Azure environment using the ARM template from Data Manager, and how the data starts flowing immediately after the Azure data input is successfully created in Data Manager.

YouTube video player

That’s how simple it is to onboard Azure Active Directory logs in Splunk using Data Manager! In case you are also interested in onboarding Azure Activity logs, all you have to do is create a new data input in Data Manager and follow the configuration steps in the Data Manager UI. For more information, please see onboarding Azure data in Data Manager.

Try out this new capability today to help you get to the cloud faster while making your data work for you.

Have feedback? Share your thoughts with us and other uses on the Splunk Community.

----------------------------------------------------
Thanks!
Sulay Shah

Related Articles

Face the Unexpected with the Stability and Resiliency of Splunk Cloud Platform
Platform
5 Minute Read

Face the Unexpected with the Stability and Resiliency of Splunk Cloud Platform

Splunk's SVP and Chief Product Officer, Garth Fort, dives into why the Splunk Cloud Platform is critical for helping customers drive stability across their ecosystems from a security, infrastructure and application perspective.
Prevent Data Downtime with Anomaly Detection
Platform
11 Minute Read

Prevent Data Downtime with Anomaly Detection

Learn how to use Machine Learning in Splunk to create an automatic alerting system for Admins that sends alerts whenever there is unexpected downtime or spike in ingestion volume.
Kickstart your Splunk App with @Splunk/Create
Platform
3 Minute Read

Kickstart your Splunk App with @Splunk/Create

Are you looking to get up and running with a new Splunk app with a sharp looking UI? Have you heard of @splunk/create? Checkout this blog and see how to go from idea, to packaged Splunk app in just a few steps.
Show it Off with Splunk TV! More Ways to Display Your Best Dashboards
Platform
2 Minute Read

Show it Off with Splunk TV! More Ways to Display Your Best Dashboards

Splunk TV lets you easily display your data on the big screen to visualize and monitor what’s going on in your business.
Splunk Cloud "Automated Private App Validation" (APAV) - General Availability
Platform
4 Minute Read

Splunk Cloud "Automated Private App Validation" (APAV) - General Availability

With the release of 8.2.2112 to Splunk Cloud Platform, we are excited to announce the general availability of "Automated Private App Validation" (APAV), removing the requirement for manual review for all of your private apps.
Splunk AR: Using Splunk AR Has Never Been Easier!
Platform
2 Minute Read

Splunk AR: Using Splunk AR Has Never Been Easier!

Splunk AR is better than ever! In this blog post, we’ll talk about these updates and go in detail about the exciting features in Splunk AR 4.0 and Splunk App for AR 2.0.
A New Way to Look Like Splunk
Platform
5 Minute Read

A New Way to Look Like Splunk

This blog kicks off a series where we talk about the entire Splunk UI Toolkit and how each part will benefit your app development process in the future.
Splunk Mobile, iPad, AR and TV in Private Networks
Platform
4 Minute Read

Splunk Mobile, iPad, AR and TV in Private Networks

Having Splunk Mobile available in your pocket is great, but what if you're not able to take advantage of it because of Defense Federal Acquisition Regulation Supplement (DFARS) requirements or security concerns? Through this blog post, you'll learn how deploying a Private Spacebridge might be the right answer!
Splunk Cloud Self-Service: Announcing The New Admin Config Service API For Private Applications
Platform
3 Minute Read

Splunk Cloud Self-Service: Announcing The New Admin Config Service API For Private Applications

Learn more about how customers can leverage the new ACS private app management to gain more value from their Splunk deployment.