The Azure Monitor Add-On for Splunk offers near real-time access to metric and log data from all of your Azure resources. Azure Monitor is Microsoft Azure’s built-in pipeline for searching, archiving, and routing your monitoring data, providing a single path for getting Azure data into Splunk.
Simply configure your resources to send log and metric data into an event hub namespace, deploy the add-on, and configure the add on with your event hub namespace details and you are ready to go. For detailed instructions, see the installation and configuration wiki.
The add-on currently supports these data types:
• Activity log, routed to event hub via a log profile
• Diagnostic logs, routed to event hub via diagnostic settings
• Metrics, routed to event hub via diagnostic settings
These data types are supported for the following Azure services:
• Activity log: All Azure services
• Diagnostic logs: Supported services and categories
• Metrics: Supported services and metric definitions
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.