Data Manager

User Manual

This documentation does not apply to the most recent version of Data Manager. For documentation on the most recent version, go to the latest release.

Onboarding for Azure data in Data Manager

Data Manager helps you set up hundreds of Azure accounts for data ingestion into your Splunk Cloud platform deployment.

Stages of onboarding

The onboarding steps are described in detail within Data Manager. The details are not duplicated here.

Onboard Microsoft Entra ID accounts

Onboarding a Microsoft Entra ID account consists of the following stages:

  1. Azure Admin completes the setup prerequisites by creating an application on the Azure portal.
  2. Configure the Data sources, Tenant ID, Client ID, Client Secret, Event Hub subscription ID, Event Hub region, and Destination.
  3. Deploy the Azure Resource Manager (ARM) Template on your Event Hub subscription.
  4. Click Review Data Input to navigate to the Data Management home page and see your data input.

This image shows an example of a single account onboarding flow.

Onboard Azure Activity Log accounts

Onboarding an Azure Activity Log account consists of the following stages:

  1. Azure Admin completes the setup prerequisites by creating an application on the Azure portal.
  2. Configure the Data sources, Tenant ID,Client ID, Client Secret, Source Subscription IDs, Event Hub Subscription ID, Event Hub Region, and Splunk Index Destination.
  3. Deploy the Azure Resource Manager (ARM) Template on your Event Hub subscription.
  4. Click Review Data Input to navigate to the Data Management home page and see your data input.

This image shows an example of a single account onboarding flow.

Last modified on 15 December, 2023
Azure prerequisites for Data Manager   About Azure Resource Manager templates

This documentation applies to the following versions of Data Manager: 1.8.3


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters