This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
splunk_integration [2022/11/19 01:02] kaduuwikiadmin created |
splunk_integration [2023/05/22 20:40] (current) |
||
---|---|---|---|
Line 3: | Line 3: | ||
{{:: | {{:: | ||
- | 1. First of all, remember the hostname of your Splunk instance - it will be needed later when configuring Kaduu to send alerts to Splunk | + | 1. First of all, remember the hostname of your Splunk |
2. Go to " | 2. Go to " | ||
+ | |||
+ | ---- | ||
{{:: | {{:: | ||
3. Add a new HTTP Event Collector by clicking the "Add New" link | 3. Add a new HTTP Event Collector by clicking the "Add New" link | ||
+ | |||
+ | ---- | ||
{{:: | {{:: | ||
4. Put any name for that collector and hit " | 4. Put any name for that collector and hit " | ||
+ | |||
+ | ---- | ||
{{:: | {{:: | ||
Line 22: | Line 28: | ||
7. Hit " | 7. Hit " | ||
+ | |||
+ | ---- | ||
{{:: | {{:: | ||
- | 8. Check all settings are valid on the Review page and hit next. Splunk will say that "Token has been created successfully" | + | 8. Check all settings are valid on the Review page and hit next. Splunk will say that "Token has been created successfully" |
+ | |||
+ | ---- | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | 9. Go to " | ||
+ | |||
+ | ---- | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | 10. Click "New Source Type" green button | ||
+ | |||
+ | ---- | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | 11. Name the source as “Kaduu”, | ||
+ | |||
+ | ---- | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | 12. On the Advanced tab you have to add 4 new entries (click “New setting” link below the list each time): | ||
+ | * '' | ||
+ | * '' | ||
+ | * '' | ||
+ | * '' | ||
+ | |||
+ | ---- | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | 13. Then go to main menu, to " | ||
+ | |||
+ | ---- | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | 14. Configure your Kaduu account to send alerts over HTTP | ||
+ | |||
+ | 15. Enter webhook URL in this form: [[https://< | ||
- | {{:: | + | ---- |
- | 9. Configure your Kaduu account to send alerts over HTTP | + | {{::spl-13.png?400 |}} |
- | 10. Enter webhook URL in this form: https://< | + | 16. Hit " |
- | 11. Hit " | + | 17. Warning! If you are not using the Cloud edition of Splunk (that is, it doesn' |