Skip to main content
Splunk Add-on for Microsoft Cloud Services app icon

Splunk Add-on for Microsoft Cloud Services

Collects data from Microsoft Azure resources, Azure Active Directory, Office 365, and Event Hubs with CIM normalization for Authentication, Change, and Endpoint domains.

Built by Splunk LLC
splunk product badge

Default Version 6.2.0
June 26, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2
CIM Version: 5.x
Rating

0

(0)

Log in to rate this app
Support
Splunk Supported
The Splunk Add-on for Microsoft Cloud Services collects telemetry and audit data from Microsoft Azure resources, Azure Active Directory, Office 365, and Azure Event Hubs. The add-on ingests resource metadata, audit logs, metrics, storage data, and consumption billing information from Azure subscriptions. It extracts fields and normalizes events to the Common Information Model (CIM) Authentication, Change, and Endpoint data models. The add-on supports multiple data collection methods including Azure Resource Manager APIs, Azure Monitor, Azure Storage tables and blobs, Azure Event Hubs, and Azure Data Explorer (Kusto) queries. It provides visibility into Azure virtual machines, network interfaces, public IP addresses, virtual networks, security groups, disks, and resource topology. The add-on includes pre-configured dashboards for monitoring data collection health, input configuration status, resource utilization, and error analysis. An alert action enables automated responses by stopping Azure virtual machines when specific conditions are met.

Categories

IT Operations, Security, Fraud & Compliance

Created By

Splunk LLC

Type

addon

Resources

Log in to report this app listing