Description:
CCX Security Operations has taken it upon ourselves to develop a CCX Add-on for AWS Products to provide further CIM compliance coverage not only for logs ingested via 'Splunk Add-on for AWS'.
This TA was built using a large dataset and endeavours to be the most CIM compliant comprehensive field extraction for AWS various products listed.
The Technical Addon is designed for ingest based on an SQS-Based S3 "Custom Data Type" via the Splunk Add-on for AWS or Syslog and is to be used on Search Heads.
Listed products supported:
Features:
Requirements:
- To retrieve AWS Network Firewall logs based on an SQS-Based S3 "Custom Data Type" is required additional Add-on 'Splunk Add-on for AWS' version 7.10.0 or higher (https://splunkbase.splunk.com/app/1876/).
- This Add-on is intended to be installed on Search Heads and where 'Splunk Add-on for AWS' inputs are configured.
- The AWS S3 VPC Flow logs ingested via syslog has the field extractions dependencies on Add-on 'Splunk Add-on for AWS' version 7.10.0 or higher (https://splunkbase.splunk.com/app/1876/) and it is required to be installed along 'CCX Add-on for AWS Products'
Requirements:
- To retrieve AWS Network Firewall logs based on an SQS-Based S3 "Custom Data Type" is required additional Add-on 'Splunk Add-on for AWS' version 7.10.0 or higher (https://splunkbase.splunk.com/app/1876/).
- This Add-on is intended to be installed on Search Heads and where 'Splunk Add-on for AWS' inputs are configured.
- The AWS S3 VPC Flow logs ingested via syslog has the field extractions dependencies on Add-on 'Splunk Add-on for AWS' version 7.10.0 or higher (https://splunkbase.splunk.com/app/1876/) and it is required to be installed along 'CCX Add-on for AWS Products'
Requirements:
- To retrieve AWS Network Firewall logs based on an SQS-Based S3 "Custom Data Type" is required additional Add-on 'Splunk Add-on for AWS' version 7.10.0 or higher (https://splunkbase.splunk.com/app/1876/).
- This Add-on is intended to be installed on Search Heads and where 'Splunk Add-on for AWS' inputs are configured.
- The AWS S3 VPC Flow logs ingested via syslog has the field extractions dependencies on Add-on 'Splunk Add-on for AWS' version 7.10.0 or higher (https://splunkbase.splunk.com/app/1876/) and it is required to be installed along 'CCX Add-on for AWS Products'
Added support for
- Application Load Balancer Access Logs
- API Gateway Access Logs
Requirements:
- To retrieve AWS Network Firewall logs based on an SQS-Based S3 "Custom Data Type" is required additional Add-on 'Splunk Add-on for AWS' version 5.0.3 or higher (https://splunkbase.splunk.com/app/1876/).
- This Add-on is intended to be installed on Search Heads and where 'Splunk Add-on for AWS' inputs are configured.
- The AWS S3 VPC Flow logs ingested via syslog has the field extractions dependencies on Add-on 'Splunk Add-on for AWS' version 5.0.3 or higher (https://splunkbase.splunk.com/app/1876/) and it is required to be installed along 'CCX Add-on for AWS Products'
Listed products supported:
- AWS Network Firewall
- AWS Web Application Firewall
Requirements:
- To retrieve AWS Network Firewall logs based on an SQS-Based S3 "Custom Data Type" is required additional Add-on 'Splunk Add-on for AWS' version 5.0.3 or higher (https://splunkbase.splunk.com/app/1876/).
- This Add-on is intended to be installed on Search Heads and where 'Splunk Add-on for AWS' inputs are configured.
Requirements:
- To retrieve AWS Network Firewall logs based on an SQS-Based S3 "Custom Data Type" is required additional Add-on 'Splunk Add-on for AWS' version 5.0.3 or higher (https://splunkbase.splunk.com/app/1876/).
- This Add-on is intended to be installed on Search Heads.
Installation:
- To retrieve AWS Network Firewall logs based on an SQS-Based S3 "Custom Data Type" is required additional Add-on 'Splunk Add-on for AWS' version 5.0.3 or higher (https://splunkbase.splunk.com/app/1876/) installed where "inputs" is to be configured.
- This Add-on is intended to be installed on Search Heads.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.