IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: How to Configure Splunk Integration

App Control: How to Configure Splunk Integration

Environment

  • App Control Server: All Supported Versions
  • Splunk Enterprise: Versions 5.0 - 7.3

Objective

This article describes how to integrate the Splunk analytics with App Control.

Resolution

  1. Login to the Console and navigate to the gear icon > System Configuration > External Analytics > Edit.
  2. In the General section: 
    • Check the box to Enable Export.
    • Specify the Export Directory (should be a local drive on the application server) & click Test.
    • Determine whether File Catalog, File Operations or Events will be included.
    • Determine whether a Limit will be enforced on the Export Directory.
  3. Specify the Splunk web server in the Root URL field.
  4. The defaults for each of the Analytics Server Reports can be filled in using the button, "Set Analytics URLs to Splunk Defaults".
  5. Click Update to save the settings.
Note: To configure the Splunk Server for integration with the App Control server, please review the following article from Splunk.

Additional Notes

  • Currently the External Analytics feature only supports Splunk Enterprise through version 7.3.
  • Integrating App Control with a newer version of Splunk will require exporting the Events using the SYSLOG option as outlined here.
  • Further information can be found in the Server Documentation > Supported Integrations section of the App Control documentation.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
34% helpful (1/3)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2742
Contributors