This page explains how to configure SIEM integration when using Splunk Cloud Platform.
Note: For detailed information on how to use Splunk, please contact Cisco, the product's provider.
- Log in to Splunk Cloud as an administrator, then click the "Find more apps" link.
- On the Browse More Apps screen, enter "trustlogin" in the app search field and search.
- When "TrustLogin addon for Splunk" appears in the search results, click the "Install" button, then log in with administrator privileges and proceed with the installation.
- After the installation is complete, click the TrustLogin app in the installed apps list to go to the configuration screen.
- On the configuration screen, click the "Create New Input" button to configure the sync settings.
- Enter each field and click "Add" to complete the setup.
Name: name
Interval: sync interval (in seconds)
Index: you can leave this as default.
Authentication token: obtain this from the TrustLogin Admin Page.
For instructions on how to obtain it, click hereDate and time to start retrieving logs
Enter this in the format YYYY-MM-DD hh:mm:ss, as shown in the exampleMaximum number of records received per request
You can set a number between 10 and 1000 - Synced data can be checked from "Search."