This page explains how to configure SIEM integration when using Splunk Enterprise.
Note: For detailed information on how to use Splunk, please contact Cisco, the product's provider.
-
Open the Splunk admin screen, and select "Manage Apps" from the menu in the upper left.
- Click "Install app from file" in the upper right of the screen.
-
Download the file here, and select it using the "Choose" button.
Click the "Open" button, then click "Upload".
-
After the upload succeeds, "GMO TrustLogin Add-on for Splunk" will appear on the admin screen, so click it.
- To create an Input for log integration, click "Create New Input".
-
Enter the required information and click the "Add" button, and log sync will start automatically.
About each field.
Name: name
Interval: sync interval (in seconds)
Index: default
Authentication token: paste the token value obtained from TrustLogin.
Date and time to start retrieving logs: YYYY-MM-DD hh:mm:ss1
Maximum number of records received per request: 10 to 1000 (a value of 30 or higher is recommended to reduce load)