Source types for the Splunk Add-on for Microsoft Cloud Services¶
The Splunk Add-on for Microsoft Cloud Services provides the index-time and search-time knowledge for Microsoft Cloud Services data in the following formats:
The ms:o365:management
source type is for backward compatibility. A similar source type, o365:management:activity
, is in the Splunk Add-on for Microsoft Office 365.
Data source |
Source type |
Event type |
API |
CIM data models |
ITSI data models |
Notes |
---|---|---|---|---|---|---|
Azure Event Hubs |
|
n/a |
n/a |
n/a |
||
Azure Event Hubs |
|
n/a |
n/a |
|||
Azure Event Hubs |
|
n/a |
n/a |
|||
Azure Event Hubs |
|
|
n/a |
|||
Azure Event Hubs |
|
n/a |
n/a |
|||
Azure Event Hubs |
|
|
n/a |
|||
Azure Resource virtualMachine |
|
|
Azure Virtual Machines REST — List |
n/a |
Inventory |
|
Azure Resource network |
|
|
n/a |
Inventory |
||
Azure Resource public |
|
n/a |
n/a |
n/a |
||
Resource virtualNetwork |
|
n/a |
n/a |
n/a |
||
Azure Resource Disk |
|
|
n/a |
Inventory, Storage |
n/a |
|
Azure Resource Image |
|
|
n/a |
Inventory, Virtual |
n/a |
|
Azure Resource Snapshot |
|
|
n/a |
Inventory, Virtual, Snapshot |
n/a |
|
Azure Resource Group |
|
|
n/a |
Inventory |
n/a |
|
Azure Resource Subscription |
|
|
n/a |
Inventory |
n/a |
|
Azure Resource SecurityGroup |
|
|
n/a |
Inventory |
n/a |
|
Azure Audit log |
|
n/a |
n/a |
|||
Azure Storage Table |
|
n/a |
n/a |
n/a |
||
Azure Storage Blob |
|
n/a |
n/a |
n/a |
||
Azure Storage Blob |
|
n/a |
n/a |
n/a |
When selected in the input, XML and JSON fields for the |
|
Azure Storage Blob |
|
n/a |
n/a |
n/a |
When selected in the input, XML and JSON fields for the |
|
Virtual Machine Metrics |
|
|
n/a |
Performance |
||
Azure Metrics |
|
n/a |
n/a |
n/a |
n/a |
|
Azure Metrics |
|
n/a |
n/a |
n/a |
n/a |
|
Azure KQL Log Analytics |
|
n/a |
n/a |
n/a |
n/a |
|
Azure KQL Log Analytics |
|
n/a |
n/a |
n/a |
n/a |
|
Azure Consumption (Billing) |
|
n/a |
n/a |
n/a |
n/a |
|
Azure Consumption (Billing) |
|
n/a |
n/a |
n/a |
n/a |