Skip to content

Configure the Splunk Add-on for Microsoft Cloud Services for Azure endpoints for international regions

Configure the Splunk Add-on for Microsoft Cloud Services for Azure endpoints from different international regions.

  1. On your Azure deployment, configure your desired region.
  2. On the machine that contains the Splunk Add-on for Microsoft Cloud Services, navigate to $SPLUNK_HOME/etc/apps/Splunk_TA_microsoft-cloudservices/local.
  3. Using a text editor, edit the following files, depending on each data collection API endpoint, to update the regional API endpoints to match the region that you configured in your Azure deployment:
Endpoint Affected configuration files Comments
Office 365 login endpoint URL splunk_ta_ms_o365_server_ucc_system_setting.conf
Office 365 management endpoint API URL splunk_ta_ms_o365_server_ucc_system_setting.conf and splunk_ta_ms_o365_api_settings.conf
Azure account setting schema (for ingesting Azure audit events) mscs_azure_accounts.conf Set the variable account_class_type stanza to 3
Azure storage account setting schema mscs_storage_accounts.conf Set the variable account_class_type stanza to 3
  1. Save your changes.
  2. Restart your Splunk Platform instance to apply the changes.