Azure Firewall logs to Splunk Cloud

Awasthi, Shubham 1 Reputation point
2021-04-13T19:07:31.933+00:00

Hi,

I have a Splunk Cloud instance and have installed https://splunkbase.splunk.com/app/3757/#/details

Can anyone suggest how can I ingest Azure Firewall Logs to my Splunk Instance?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
662 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. suvasara-MSFT 10,041 Reputation points
    2021-04-14T09:45:16.31+00:00

    @Awasthi, Shubham , Looks like I have responded to your thread earlier. AFAIK, Splunk should have a similar addon like NSG flow logging for AZF. Having said that, it's still looking possible when crossed this addon named "Azure Log Analytics Kusto Grabber". I would recommend you test this addon in your case. AZ Firewall logs needs Log analytics integration and from there you should be able to grab those reports using kusto's and land them on custom Splunk dashboard.


    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.