<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Beyond Trust Remote Support SaaS integration with Splunk in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/740613#M3632</link>
    <description>&lt;P&gt;Thanks for your inputs here Kiran, however, it does look like that integration guide is for Beyond Trust Remote Support integration &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Mohammed.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Mar 2025 16:07:17 GMT</pubDate>
    <dc:creator>mohsplunking</dc:creator>
    <dc:date>2025-03-03T16:07:17Z</dc:date>
    <item>
      <title>Beyond Trust Remote Support SaaS integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/711576#M3576</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;&lt;P&gt;Checking if anyone has successfully integrated Beyond Trust RS SaaS with Splunk , their official guide only talks about on-prem integration where a Middleware connector needs to be installed, but for Cloud Remote Support application how this can be achieved , is there a Custom TA for REST or a HEC can be used here.&lt;/P&gt;&lt;P&gt;Appreciate some assistance here,&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Moh.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 09:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/711576#M3576</guid>
      <dc:creator>mohsplunking</dc:creator>
      <dc:date>2025-02-14T09:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Beyond Trust Remote Support SaaS integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/711604#M3577</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234071"&gt;@mohsplunking&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer to this documentation, where they have specified integration using an HEC token.&amp;nbsp;&lt;SPAN&gt;You can use Splunk's HTTP Event Collector to forward data from BeyondTrust to Splunk. This method involves creating an HTTP Event Collector in Splunk and configuring BeyondTrust to send events to this collector&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.beyondtrust.com/insights/docs/splunk" target="_blank" rel="noopener"&gt;https://docs.beyondtrust.com/insights/docs/splunk&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.beyondtrust.com/rs/docs/splunk" target="_blank" rel="noopener"&gt;Splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 12:47:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/711604#M3577</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-02-14T12:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Beyond Trust Remote Support SaaS integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/740613#M3632</link>
      <description>&lt;P&gt;Thanks for your inputs here Kiran, however, it does look like that integration guide is for Beyond Trust Remote Support integration &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Mohammed.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/740613#M3632</guid>
      <dc:creator>mohsplunking</dc:creator>
      <dc:date>2025-03-03T16:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Beyond Trust Remote Support SaaS integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/740623#M3633</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234071"&gt;@mohsplunking&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;Since BeyondTrust Remote Support SaaS is a cloud offering, the integration likely relies on its API capabilities or syslog forwarding features that can be directed to Splunk Cloud.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;HEC&amp;nbsp;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Splunk Cloud supports HEC, which allows you to send data over HTTPS using a token-based authentication method. If BeyondTrust Remote Support SaaS can send event data (e.g., session logs) to a custom endpoint, HEC could ingest this data directly.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Custom TA for REST API&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Check BeyondTrust’s documentation or contact their support to confirm the availability of a REST API for the SaaS version.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Build a Custom TA.&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Install the “REST API Modular Input” app from Splunkbase (if supported in your Splunk Cloud environment; you may need to request Splunk Support to install it).&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Configure a REST input with the BeyondTrust API URL, authentication (OAuth or API key), and polling interval (e.g., every 60 seconds).&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Write props.conf and transforms.conf in the TA to parse the API response (likely JSON) into meaningful fields for Splunk.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Syslog Forwarding with an Intermediary&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;In the BeyondTrust admin interface, set up syslog forwarding to a server you control (e.g., IP address and port like 514 for UDP or TCP.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Deploy a Splunk Universal Forwarder on a small VM or container. Configure it to listen for syslog data and forward it to Splunk Cloud using outputs.conf.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyond-Trust-Remote-Support-SaaS-integration-with-Splunk/m-p/740623#M3633</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T16:54:55Z</dc:date>
    </item>
  </channel>
</rss>

