Data Manager

User Manual

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Data Manager. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Modify your Azure data inputs

Perform modifications to your existing Azure data inputs in Data Manager.

Edit your Azure data inputs for Data Manager

Consider a scenario where you onboarded data for Microsoft Azure accounts, and you need to to edit your data inputs after onboarding.

If your Client Secret has expired, you will have to enter and submit a valid one. Without a valid Client Secret, you cannot save the edits to your input.

  1. From the Splunk Cloud home page, select Data Manager from the Apps menu.
  2. From the Data Management page, find the Azure data input you want to revise, and click the Edit action.
  3. Make edits to your data input.
  4. Based on the edits to your data input, update the diagnostic settings on your subscriptions.

Delete an Azure data input

You can delete your Azure Active Directory data inputs from the Azure CLI or from the Powershell CLI using the steps in the Data Manager app. For Azure Activity Logs, only the Powershell CLI is supported.

Before deleting this data input configuration, you need to clean up the Azure setup. The Azure cleanup process cannot be canceled or paused, while in progress.

Delete an Azure Activity Logs input

  1. Clean up your Azure resources configurations.
  2. After you clean up the Azure deployment, click the Delete Data Input button to delete your data input.

Delete an Azure Active Directory Logs input

  1. Delete the diagnostic settings from your Azure Portal.
  2. Clean up your Azure resources configurations.
  3. After you clean up the Azure deployment, click the Delete Data Input button to delete your data input.
Last modified on 10 January, 2023
PREVIOUS
Verify the data input for Azure in Data Manager
  NEXT
Dashboards overview

This documentation applies to the following versions of Data Manager: 1.8.1


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters