Create a Microsoft Azure connection
Create a Microsoft Azure connection in the Data Management app to authenticate federated searches over datasets in Azure Data Lake Storage and Azure Blob Storage.
Create a Microsoft Azure connection in the Data Management app to authenticate federated searches over datasets in Azure Data Lake Storage and Azure Blob Storage containers from your Splunk platform deployment.
The Microsoft Azure connection uses a Microsoft Entra app registration to authenticate your ability to run federated searches over remote datasets in Azure Data Lake Storage and Azure Blob Storage containers. You can create multiple datasets that use the same connection.
To create a connection for federated search over a Microsoft Azure dataset, your Splunk Cloud Platform deployment user account must have a role with the with the edit_datasets and edit_federated_providers capabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual.
To allow the Splunk platform to access Microsoft Azure through your connection, complete the following tasks in Microsoft Entra ID:
| Task | Microsoft Entra documentation |
|---|---|
| Create an app registration for your connection. | Register an application in Microsoft Entra ID |
| Add a client secret to the app registration. | Add and manage application credentials in Microsoft Entra ID |
| Grant the Storage Blob Data Contributor role to the app registration for your connection. | Assign Azure roles using the Azure portal |
Keep your app registration information open in a separate browser tab throughout the connection creation process, so that you can retrieve the required values for authenticating your connection and configuring your dataset.
After you create a connection to your Azure storage account, define a dataset for that connection. See Define a Microsoft Azure dataset.