Configure the Splunk Add-on for Microsoft Cloud Services for Azure endpoints for international regions¶
Configure the Splunk Add-on for Microsoft Cloud Services for Azure endpoints from different international regions.
- On your Azure deployment, configure your desired region.
- On the machine that contains the Splunk Add-on for Microsoft Cloud Services, navigate to
$SPLUNK_HOME/etc/apps/Splunk_TA_microsoft-cloudservices/local.
- Using a text editor, edit the following files, depending on each data collection API endpoint, to update the regional API endpoints to match the region that you configured in your Azure deployment:
Endpoint | Affected configuration files | Comments |
---|---|---|
Office 365 login endpoint URL | splunk_ta_ms_o365_server_ucc_system_setting.conf | |
Office 365 management endpoint API URL | splunk_ta_ms_o365_server_ucc_system_setting.conf and splunk_ta_ms_o365_api_settings.conf | |
Azure account setting schema (for ingesting Azure audit events) | mscs_azure_accounts.conf | Set the variable account_class_type stanza to 3 |
Azure storage account setting schema | mscs_storage_accounts.conf | Set the variable account_class_type stanza to 3 |
- Save your changes.
- Restart your Splunk Platform instance to apply the changes.