Beyond Identity is integrated with Splunk SIEM. This integration allows Beyond Identity Splunk Add-on to pull event log data from Beyond Identity’s cloud using a data export API. This User Guide provides documentation to install and set-up this integration. It covers all the details needed to successfully setup the Add-on on a local Splunk Enterprise 8.x instance. It also provides a quick overview of the Add-on.
2.1 You will need to have access to an instance of Splunk Enterprise 8.x or above. Please follow the instructions, as provided by Splunk, for the installation of Splunk Enterprise 8.x or above.
2.2 You will need the Beyond Identity Splunk Add-on. It can be downloaded from the following link: https://splunkbase.splunk.com/app/5622/
Installation instructions are given further down in this document.
2.3 To be able to view the CIM visualizations, the CIM package needs to be downloaded from the following link: https://splunkbase.splunk.com/app/1621/
Installation instructions are given further down in this document.
3.1 Login with your administrator credentials into the Splunk Enterprise.
3.2 You will land on the “Dashboard” screen.
3.3 On the “Dashboard” screen, on the top left corner, click on the gear icon next to “Apps” and you will be navigated to the “Manage Apps” screen. On this screen, you will notice a few Splunk apps that are already installed by default.
3.4 Click on the “Install app from file” button, click on “Choose File”, select the “.tgz” file (downloaded in Step 2.2) and upload it by clicking on the “Upload” button. (If you are uploading for the first time, do not click the “Upgrade App” checkbox.)
3.5 After Uploading the “.tgz” file, click on “Restart Now”.
3.6 Now login again, click on “Apps” dropdown and check whether the “Beyond Identity” App is available.
3.6.1 Click on “Settings” in the top navigation bar (towards the right).
3.6.2 Click on “Indexes” > “New Index”
3.6.3 Enter the index name and select the app name from the app section and save the index.
3.6.4 Click on “Apps” >”Beyond Identity”, click on the “Create New Input” button and fill in all the required fields and select index from index dropdown (if user created the index, otherwise it will be the default index.)
Field Name | Description |
---|---|
Name | Any unique name can be entered here. Space character is not allowed. |
Interval | The interval after which the data will be pulled in to Splunk. (For example, if 100 is given, after every 100 seconds, data will be pulled in to Splunk.) |
Index | Splunk has an index feature. The log types which will be retrieved in Splunk are saved against an index. The index is set to default or the created index. |
API URL | https://dataexport-public.byndid.com/v1/events |
API Key | Enter the API Key provided by Beyond Identity to authorize the user for retrieving data via the API. |
Start Date | Enter the Start date from which to pull the data. The default is 7 days back. |
3.6.5 After the new input is created, the Inputs screen will populate.
3.6.6 On the search bar, write query index="index_name" (if index is created, otherwise go to 3.6.7 steps.)
3.6.7 Click on “Search” > “How to Search” > “Data Summary” > “SourceTypes”.
4.1 Install the CIM mapping Add-on “.tgz” file (downloaded in Step 2.3) similar to Beyond Identity Splunk Add-on installation (Step 3.4).
4.2 Click on “Settings” > “Data Models”
4.3 Click on “Authentication”
4.4 Click on “Pivot”
4.5 Click on “Authentication”.
4.6 Click on the “Pie Chart” on the left navigation bar and click on “Add Color”, select “src”.
Follow similar steps for other CIM mapping models and corresponding fields.
To uninstall the Add-on from Splunk Enterprise, run the following command from bin directory:
./splunk remove app <appname>
Overview:
This Beyond Identity add-on enables customers to view their authentication events such as: successful logins, failed login attempts. Customers are able to get in depth information about IPS and location of login attempts.
Beyond Identity Splunk Add-on :
Beyond Identity add-on enables customers to view their authentication events such as: successful logins, failed login attempts. Customers are able to get in depth information about the IPs and location of login attempts.
Supported Versions
Splunk Enterprise: Version 8.1
Python: Version 3.6
Release Notes
Version 1.0.0
Features:-
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.