@Cliff - Thanks for the question and using MS Q&A platform.
It seems like you are trying to stream data from Intune to Splunk using Event Hub, but you are facing some issues with the configuration. I can definitely help you with that.
Event Hub is a good option to use for streaming data from Intune to Splunk. However, there could be several reasons why you are not seeing any messages coming through on the Event Hub side. Here are a few things you can check:
Make sure that the diagnostic settings in Intune are configured correctly. Double-check the settings to ensure that you have selected the correct log categories and that the destination is set to stream to an Event Hub.
Check if the Event Hub namespace is configured correctlly. Make sure that you have created the Event Hub namespace and that it is associated with the correct subscription.
Verify that the Event Hub policy name is correct. Make sure that you have created the policy name and that it has the correct permissions to send messages to the Event Hub.
If you have checked all of the above and are still not seeing any messages coming through, you can try enabling diagnostic logs in Intune and checking the logs to see if there are any errors or issues. You can also try using a different destination, such as Log Analytics, to see if you are able to stream data successfully.
For more details, refer to Send log data to storage, event hubs, or log analytics in Intune.
Hope this helps. Do let us know if you any further queries.
If this answers your query, do click Accept Answer
and Yes
for was this answer helpful. And, if you have any further query do let us know.