Create a Microsoft Azure dataset for Ingest Processor pipelines
Create a Microsoft Azure dataset in the Data Management app to define the Azure storage container that your pipelines send data to.
To send data from Ingest Processor to an Azure Blob Storage container or an Azure Data Lake Storage container, you must create a Microsoft Azure dataset in the Data Management app on Splunk Cloud Platform. You can then use the dataset as a pipeline destination.
You can optionally configure the dataset to also support federated searches, so that you can use the same dataset to write and read data from Microsoft Azure.
The dataset uses a Microsoft Azure connection for authentication. You can create multiple datasets that use the same connection.
- Your Splunk Cloud Platform deployment must be on version 10.4.2604 or higher.
- Your user account on the Splunk Cloud Platform deployment must have the
edit_datasetsandadmin_all_objectscapabilities. For more information, see the following pages:- Manage users for the Ingest Processor solution
- Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual
-
You must have a Microsoft Azure connection that authenticates to the Azure storage container that you want the dataset to represent. For more information, see Create a Microsoft Azure connection for Ingest Processor pipelines.
You now have a Microsoft Azure dataset that can access the data in your Azure container.
To send data from Ingest Processor to your Azure container, create a pipeline that uses the Microsoft Azure dataset as a destination. Then, apply the pipeline to Ingest Processor. For more information, see the following pages:
For information about running federated searches on Microsoft Azure datasets, see Run federated searches over Microsoft Azure datasets in the Splunk Cloud Platform Federated Search manual.