<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Akamai logs to Splunk in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740493#M81606</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;If you don't have a heavy forwarder and need to install the add-on, you can install it on the search head cluster. Please refer to the documentation below for more details and installation instructions.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall" target="_blank"&gt;Install an add-on in a distributed Splunk Enterprise deployment - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;To deploy an add-on to the search head cluster members, use the deployer. &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.1/DistSearch/PropagateSHCconfigurationchanges" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.1/DistSearch/PropagateSHCconfigurationchanges&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Mar 2025 07:54:14 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-03-02T07:54:14Z</dc:date>
    <item>
      <title>Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740489#M81602</link>
      <description>&lt;P&gt;Anyone please help me how to get Akamai logs to Splunk. We have clustered environment with syslog server uf installed in it and forwards data to our Deployment Server initially and then it deployes to Cluster Manager and Deployer. We have 6 indexers with 2 indexers in each site (3 site multi cluster). 3 search heads one in each site. How to proceed with this?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 07:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740489#M81602</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-03-02T07:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740490#M81603</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please follow this&amp;nbsp;&lt;A href="https://techdocs.akamai.com/siem-integration/docs/siem-splunk-connector" target="_blank"&gt;SIEM Splunk connector&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 07:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740490#M81603</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-02T07:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740491#M81604</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Install the add-on on your heavy forwarder and configure it. You have two options for sending logs to Splunk:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Install the add-on on your heavy forwarder and use it to send logs to Splunk.&lt;/LI&gt;&lt;LI&gt;If Akamai supports syslog, you can send logs to your syslog forwarder, which will then forward them to Splunk. In this case, please configure syslog-ng or rsyslog to capture Akamai logs in a specific directory and create the necessary inputs to onboard the logs into Splunk.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Configure the UF on your syslog server to monitor the log files. Update the inputs.conf file to specify the log file paths and the outputs.conf file to forward the data to your indexe&lt;/P&gt;&lt;P&gt;Example inputs.conf:&lt;/P&gt;&lt;PRE&gt;[monitor:///var/log/akamai/*.log]&lt;BR /&gt;index = akamai&lt;BR /&gt;sourcetype = akamaisiem&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 07:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740491#M81604</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-02T07:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740492#M81605</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;I recommend using the add-on. &lt;A href="https://splunkbase.splunk.com/app/4310" target="_blank"&gt;Akamai SIEM Integration | Splunkbase&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 07:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740492#M81605</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-02T07:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740493#M81606</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;If you don't have a heavy forwarder and need to install the add-on, you can install it on the search head cluster. Please refer to the documentation below for more details and installation instructions.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall" target="_blank"&gt;Install an add-on in a distributed Splunk Enterprise deployment - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;To deploy an add-on to the search head cluster members, use the deployer. &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.1/DistSearch/PropagateSHCconfigurationchanges" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.1/DistSearch/PropagateSHCconfigurationchanges&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 07:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740493#M81606</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-02T07:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740494#M81607</link>
      <description>&lt;P&gt;I am stuck at this point --&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Click the Akamai Security Incident Event Manager API.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I can't find this in data inputs after installing add-on.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 08:01:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740494#M81607</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-03-02T08:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740499#M81608</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to &lt;STRONG&gt;Settings &amp;gt; Data Inputs&lt;/STRONG&gt;, where you will find the Akamai data input.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 09:45:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740499#M81608</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-02T09:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740502#M81609</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the pre-requisites .&amp;nbsp;&lt;A href="https://techdocs.akamai.com/siem-integration/docs/siem-splunk-connector" target="_blank"&gt;https://techdocs.akamai.com/siem-integration/docs/siem-splunk-connector&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 10:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740502#M81609</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-02T10:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740506#M81610</link>
      <description>&lt;P class="lia-align-left"&gt;Not able to find.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 11:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740506#M81610</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-03-02T11:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Akamai logs to Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740508#M81611</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Please verify the prerequisites.&amp;nbsp;&lt;SPAN&gt;It's a Java issue, you need to make sure Splunk can access Java.&amp;nbsp; I can see some solutions that, they are able to see the data inputs using the below steps:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Fixed the issue by adding the config in inputs.conf"[TA-Akamai_SIEM]#disable the running introspection.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;run_introspection=false&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37933i481AFF9B9B1F43D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 13:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Akamai-logs-to-Splunk/m-p/740508#M81611</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-02T13:00:05Z</dc:date>
    </item>
  </channel>
</rss>

