Documentation:
Refer to the Admin Guide from your Entrust Identity as a Service account for assistance.
Configuration:
Before configuring the add-on, customers must create a Splunk application prior to this step. See the Identity as a Service Admin Online Help for more information.
To configure your add-on, complete the following steps after downloading and installing the add-on:
1. Create a new input for your Identity as a Service source.
2. Select the category of logs you would like to import from Identity as a Service into Splunk. The categories are:
a. Authentication Events
b. Management Events
c. Both (By default both categories are selected)
3. Enter the interval (in seconds) to set the frequency that audit logs in Identity as a Service are imported into Splunk. The interval cannot be less than 30 seconds. The first time the add-on is enabled, all events are imported into Splunk. After that, events are imported at the set interval rate.
4. Under Configuration > Add-on Settings enter the json value that was created when you added a Splunk application in Identity as a Service.
Upon successful configuration, this add-on will automatically import all previously logged audits for the specified category into Splunk.
Once the data source is enabled and data is being pulled in, administrators can create dashboards with Identity as a Service audit data.
This version is rebuilt based on Splunk Add-on Builder 4.4.1 to resolve Splunk SDK Python dependency issue. No function changes.
Support Splunk Enterprise platform version 9.4, 9.3, 9.2
Version 1.6.1, built with the latest Add-on Builder version 4.1.4. No other function changes. Support upgrade from previous version (1.6.0).
This is built with the latest version of Add-on Builder version 4.1.3. Note that we don't support an upgrade to this version, but rather a full installation.
Updated to support the latest Splunk platform.
Timezone bug fix.
Support for Splunk Cloud.
• Support for Splunk Cloud.
• Product Rebranding.
Updated for Splunk 8.
Updated the supported Splunk versions to include 7.3.
Version 1.0.0
- Initial Release
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.