Azure Activity Logs Tutorial | Integrating Activity Logs with Splunk via EventHub @ Subscription

Опубликовано: 11 Май 2026
на канале: CyberSatrix
15,775
187

Microsoft Azure Activity logs provide insights into the Subscription, Resource Groups, or specific resource level events. The information can include when a resource is created, deleted or in the case of VM when it has been started or shutdown, It is also really helpful to get an insight about the API calls made by the user to access the machine.

As mentioned in the video please find the link for a detailed understanding of the Microsoft Azure Event Hub
   • Azure Event Hub Tutorial & Arch. | Event H...  

Please find the below topics covered in this video
00:46 Agenda
01:13 Azure Event Hub Architecture
05:09 Visualizing Data flow
07:59 Explaining Hands-On Steps
10:03 Pre-Requisite
11:17 Creation of Event Hub Namespace
13:33 Creation of Event Hub & Consumer Group
14:45 Understanding Shared Acess policies
16:24 Creation of Azure AD application - App Registration
17:30 Assigning API permission to registered Application
19:35 Assigning roles to application
21:24 Creation of client secrets for the registered application
22:35 Understanding Splunk Add-On for Microsoft Cloud Services Ver:4.1.3
23:46 Configure the Azure App account on Splunk Add -On
25:13 Configure the Input (Azure Event Hub) on Splunk Add-On
28:42 Enable Activity Log Diagnostic Settings at the Subscription level
31:42 Validation logs on Splunk

****** WATCH OUT FOR THE BELOW SECTION FOR LINKS MENTIONED IN THE SESSION *****
Splunk Links and Docs
https://splunkbase.splunk.com/app/3110/
https://docs.splunk.com/Documentation...
https://docs.splunk.com/Documentation...
https://docs.splunk.com/Documentation...
Azure Links and Docs
https://docs.microsoft.com/en-us/azur...
https://docs.microsoft.com/en-us/azur...


********** WATCH THIS SECTION FOR MY OTHER VIDEOS ***********
Azure Event Hub Deep Dive Understanding -    • Azure Event Hub Tutorial & Arch. | Event H...  
Launching AWS instance in AWS Console -    • AWS : How to Launch a Linux Instance  
Terraform Introduction and Installation -    • Launching AWS Instance using Terraform - P...  
Terraform code to set up basic infrastructure in AWS provider -    • Launching AWS Instance using Terraform - P...  
Terraform code to access the Instance using different methods -    • Launching AWS Instance using Terraform - P...  
SIEM SPLUNK | GuardDuty | AWS GuardDuty Integration with Splunk via AWS S3 Bucket -
   • SIEM SPLUNK | GuardDuty | AWS GuardDuty In...  
SPLUNK | SQS | EVENT BRIDGE | GuardDuty | Amazon SQS Queue to Onboard GuardDuty Findings to Splunk
   • SPLUNK | SQS | EVENT BRIDGE | GuardDuty | ...  
AWS | Security Hub | Introducing Security Hub | Single platform for all Cloud Security services
   • AWS | Security Hub | Introducing Security ...  
AWS | Security Hub | Splunk | Integrating AWS Security Hub with Splunk via Amazon Event Bridge
   • AWS | Security Hub | Splunk | Integrating ...