Modify your Azure data inputs
Perform modifications to your existing Azure data inputs in Data Manager.
Edit your Azure data inputs for Data Manager
Consider a scenario where you onboarded data for Microsoft Azure accounts, and you need to to edit your data inputs after onboarding.
- From the Splunk Cloud home page, select Data Manager from the Apps menu.
- From the Data Management page, find the Azure data input you want to revise, and click the Edit action.
- Deploy your edited ARM template.
You cannot edit the Data Input Name and Tenant ID fields, but the rest of the fields can be changed.
When editing an Azure data input source, interval, or endpoint in Data Manager, the data ingestion silently fails with no error messages. However, an "Invalid Client Secret" message displays in the Azure logs. This happens because Data Manager does not store the client secret. The workaround for all edit scenarios is to reenter the client secret in the Data Inputs page of Data Manager.
Delete an Azure data input
You can delete your Azure data inputs from the Azure CLI or from the Powershell CLI using the steps in the Data Manager app.
For Azure Activity Logs, only the Powershell CLI is supported
Before deleting this data input configuration, you need to clean up the Azure setup. The Azure cleanup process cannot be canceled or paused, while in progress.
- Delete the diagnostic settings from your Azure Portal.
- Clean up Azure resources configurations.
- After you clean up the Azure deployment, click the Delete Data Input button to delete your data input.
Verify the data input for Azure in Data Manager | Dashboards overview |
This documentation applies to the following versions of Data Manager: 1.7.0
Feedback submitted, thanks!