Refer to the http://files.observeit.com/docs/Splunk-ObserveIT-User-Guide.pdf">User Guide or follow instructions below.
Hardware Requirements:
Refer to http://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements">System Requirements document
Software Requirements:
Installing on stand-alone Splunk instance
Refer to http://docs.splunk.com/Documentation/AddOns/released/Overview/Singleserverinstall">Splunk Documentation for instructions
Installing TA-ObserveIT in a distributed Splunk Enterprise deployment
Install the TA on a non-clustered search head or a heavy forwarder.
Name Descriptive name
Interval API polling interval in seconds
Index Destination index. Either select index name from a
drop-down list or type index name. Make sure the index
exists at your deployment's indexing tier before saving
input configuration.
Reports API URL ObserveIT API URL.Non-secure connections are not
supported.
e.g.: https://_MACHINE_NAME_/v2/apis/report;realm=observeit/reports
Client ID ObserveIT API token. To obtain the token:
1. Navigate to https://_MACHINE_NAME_/v2/apps/portal/home.html
2. Press on 'Credentials' tab
3. Press on 'Create App' button
4. Press on the create application name
5. Press on Generate Token button
6. Look for "access_token" in JWN Token area
Client Secret Client secret for Client ID above
Historical Data ... To include existing events on your system, select the time period
you want to go back to.
Select None, if you want only new events to be loaded
Collected reports Reports data to collect. Can "User Activity", "Alerts", etc...
CA Certificate Chain CA certificate (mandatory). You must provide the path to CA certificate
chain file, relative to $SPLUNK_HOME. Default CA certificates will be
used if no file name provided.
Example: cer\itmdemo-sales-demo-ca.cer
Search ta_observeit_observeit_api.log for non-INFO messages:
index=_internal sourcetype="ta:observeit:log" NOT "INFO"
For support configuring or using the ObserveIT Add-On for Splunk, please
contact us at oit-support@proofpoint.com. Support is provided during weekday
business hours (US, West Coast)
For help using the ObserveIT platform, please contact the ObserveIT support
organization. https://www.observeit.com/support/
TA-ObserveIT is provided under Apache License version 2.0
The TA was created using Splunk Add-on Builder App. http://docs.splunk.com/Documentation/AddonBuilder/2.2.0/UserGuide/Thirdpartysoftwarecredits">Third-party software credits
Added support for report types:
– Audit Configuration
– Audit Logins
– Audit Saved sessions
– Audit Session Playback
– System Events
– User DBA Activity
– User Messaging Actions Activity
– User Session
Rebuilt with recent AOB version
python3-only version
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.