Splunk HEC to Azure Monitor

abk 0 Reputation points
2023-03-29T01:51:26.5633333+00:00

Hi legends,

I am working with a SaaS based product that has OOTB integration with Splunk HEC. However, the company I work for does not use Splunk, it uses Azure Monitor and App Insights. Is there a way to redirect Splunk HEC requests from the source to Azure Monitor?

thanks,

abk

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,182 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Brendon Mathew 0 Reputation points
    2023-03-29T05:30:42.8666667+00:00

    Please understand the pre-requisite before you do that:

    1. Understand your current usage
    2. Set up a Log Analytics workspace
    3. Migrate Splunk artifacts to Azure Monitor
    4. Collect data
    5. Transition to Azure Monitor Logs

    Well detailed i cant explain right here, but you can get someone to help with that.


  2. Maxim Sergeev 6,571 Reputation points Microsoft Employee
    2023-04-05T00:22:49.1466667+00:00

    Hi there, It's way easier to just install Azure Monitor Agent to the collector and send the required telemetry (I assume security logs) from the collector to Azure Monitor directly. Yes, Azure Monitor allows you to collect telemetry by API, but at the end the solution will look overcomplicated.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.