Hardware and software requirements for the Splunk Add-on for Microsoft Cloud Services¶
To install and configure the Splunk Add-on for Microsoft Cloud Services, you must be a member of the admin or sc_admin role.
You do not need a special role to use this add-on’s troubleshooting dashboard.
Microsoft account and related modular inputs¶
The Splunk Add-on for Microsoft Cloud Services uses two types of Microsoft accounts to collect data: the Azure App account and the Azure Storage account.
- If you want to collect data from the Azure Audit, Azure Resource, Azure Metrics, Azure Consumption (Billing) and Azure KQL inputs, you must first apply for an Azure app account. Then, connect your Azure app account to the Splunk Add-on for Microsoft Cloud Services.
- If you want to collect data from the Azure Storage Table input, which includes virtual machine metrics, or the Azure Storage Blob input, you must first apply for an Azure Storage account. Then, connect your Azure Storage account to the Splunk Add-on for Microsoft Cloud Services.
Microsoft account permission requirements¶
To collect data from Azure audit and Azure resources, you must configure an Azure Active Directory Application with read permissions. See Add permissions to your Active Directory Application.
To collect data from Azure storage table and Azure storage blob, see configure the storage account to get data.
Azure Government Cloud limitations¶
The Splunk Add-on for Microsoft Cloud Services has not been tested with Azure Government Cloud. The functionality of the Splunk Add-on for Microsoft Cloud Services responsible for Azure Government Cloud data is not supported and is provided “as is”, and should be used at your own risk.
Performance reference for the Splunk Add-on for Microsoft Cloud Services¶
For reference information about each performance tested inputs for the Splunk Add-on for Microsoft Cloud services, see the following topics in this manual:
- Performance reference for the Azure Event Hub input in the Splunk Add-on for Microsoft Cloud Services
- Performance reference for the Azure Storage input in the Splunk Add-on for Microsoft Cloud Services
- Performance reference for the Azure Storage Blob input in the Splunk Add-on for Microsoft Cloud Services
Many factors impact performance results, including file size, file compression, event size, deployment architecture, batch size for Event Hub file size, and hardware. Results represent reference information and do not represent performance in all environments.
Splunk platform requirements¶
Because this add-on runs on the Splunk platform, all the system requirements apply for the Splunk software that you use to run this add-on.
- For Splunk Enterprise system requirements, see System requirements for use of Splunk Enterprise on-premises in the Splunk Enterprise Installation Manual.
- If you are managing on-premises forwarders to get data into Splunk Cloud Platform, see System requirements for use of Splunk Enterprise on-premises in the Splunk Enterprise Installation Manual, which includes information about forwarders.
For information about installation locations and environments, see Install the Splunk Add-on for Microsoft Cloud Services.
Support for macOS¶
The Splunk Add-on for Microsoft Cloud Services has not been tested with any versions of the macOS operating system. Running the Splunk Add-on for Microsoft Cloud Services is not supported and is provided “as is”, and should be used at your own risk.