Data Manager

User Manual

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Data Manager. Click here for the latest version.
Acrobat logo Download topic as PDF

Modify your Azure data inputs

Perform modifications to your existing Azure data inputs in Data Manager.

Edit your Azure data inputs for Data Manager

Consider a scenario where you onboarded data for Microsoft Azure accounts, and you need to to edit your data inputs after onboarding.

  1. From the Splunk Cloud home page, select Data Manager from the Apps menu.
  2. From the Data Management page, find the Azure data input you want to revise, and click the Edit action.
  3. Deploy your edited ARM template.

You cannot edit the Data Input Name and Tenant ID fields, but the rest of the fields can be changed.

When editing an Azure data input source, interval, or endpoint in Data Manager, the data ingestion silently fails with no error messages. However, an "Invalid Client Secret" message displays in the Azure logs. This happens because Data Manager does not store the client secret. The workaround for all edit scenarios is to reenter the client secret in the Data Inputs page of Data Manager.

Delete an Azure data input

You can delete your Azure data inputs from the Azure CLI or from the Powershell CLI using the steps in the Data Manager app.

For Azure Activity Logs, only the Powershell CLI is supported

Before deleting this data input configuration, you need to clean up the Azure setup. The Azure cleanup process cannot be canceled or paused, while in progress.

  1. Delete the diagnostic settings from your Azure Portal.
  2. Clean up Azure resources configurations.
  3. After you clean up the Azure deployment, click the Delete Data Input button to delete your data input.

Last modified on 07 September, 2022
PREVIOUS
Verify the data input for Azure in Data Manager
  NEXT
Dashboards overview

This documentation applies to the following versions of Data Manager: 1.7.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters