<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SplunkCloud Kiteworks integration in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741147#M3657</link>
    <description>&lt;P&gt;Hi Will,&lt;/P&gt;&lt;P&gt;Did you separate them just by a text editor. Or you did additional steps? (e.g passphrase to decrypt the pem file, ssl password if needed , etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;</description>
    <pubDate>Fri, 07 Mar 2025 16:26:53 GMT</pubDate>
    <dc:creator>Paaattt</dc:creator>
    <dc:date>2025-03-07T16:26:53Z</dc:date>
    <item>
      <title>SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741088#M3651</link>
      <description>&lt;P&gt;Need some guidance on SplunkCloud Kiteworks integration. We are utilizing built-in UF of Kiteworks found on admin console and sending it directly to cloud. Did you use the forwarder app package and how did you it? I don't have access to the client's KW console. All I know is currently it is asking us to upload 4 certificate files for tls and not the forwarder package app. The Splunk Cloud and Splunk Enterprise toggle button as well is disabled which is weird. I believe on lower version there no option for that but we have.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 08:35:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741088#M3651</guid>
      <dc:creator>Paaattt</dc:creator>
      <dc:date>2025-03-07T08:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741109#M3655</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234516"&gt;@Paaattt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using Splunk Cloud as your destination? If so you'll need to download the UF app download package which will contain your certificates, and if not you'll need to gather them from your Splunk Enterprise deployment (the location may depend on your setup).&lt;/P&gt;&lt;P class=""&gt;Kiteworks requires separate files for the server certificate, intermediate certificate, root certificate, and private key for TLS setup. Typically for Splunk we combine these in a single PEM file, but Kiteworks needs them as distinct files.&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Obtain your Splunk PEM certs, this would be inside the UF forwarder app if you're using Splunk Cloud.&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Split out the certs/keys into individual&amp;nbsp;certificates (server, intermediate, root) and the private key in separate files.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Verify that the certificates are in the correct format (PEM) and the private key is in RSA format&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Once you have these files you should be able to upload these to KiteWorks which will then hopefully allow you to enable to output to Splunk.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 12:38:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741109#M3655</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-07T12:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741147#M3657</link>
      <description>&lt;P&gt;Hi Will,&lt;/P&gt;&lt;P&gt;Did you separate them just by a text editor. Or you did additional steps? (e.g passphrase to decrypt the pem file, ssl password if needed , etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 16:26:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741147#M3657</guid>
      <dc:creator>Paaattt</dc:creator>
      <dc:date>2025-03-07T16:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741158#M3658</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234516"&gt;@Paaattt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ye the file is ultimately a text file so you can use any regular text editor to edit and copy the contents into new files.&lt;/P&gt;&lt;P&gt;Good point about the encrypted key, Does Kiteworks offer a field for SSL Password (which will be in your UF app). If not you will need to remove the encrpytion from the key before you add it to Kiteworks&lt;/P&gt;&lt;P&gt;Use something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;openssl rsa -in encrypted_key.pem -out decrypted_key.pem&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;When you run this command, OpenSSL will prompt you to enter the current password for the private key. After you provide the correct password, it will output the decrypted private key to the specified output file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 17:34:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741158#M3658</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-07T17:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741218#M3660</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you. So Kiteworks accepts the following&lt;/P&gt;&lt;P&gt;SSL certificate&lt;BR /&gt;SSL Password&lt;BR /&gt;Root Certificate&lt;BR /&gt;Intermediate Certificate&lt;BR /&gt;&lt;BR /&gt;So yeah I can move them to separate pem file. My remaining problem is the SSL Password key. Splunk told me that the passphrase is located in&amp;nbsp;$SPLUNK_HOME/etc/apps/100_**/local/outputs.conf.&lt;BR /&gt;[tcpout]&lt;BR /&gt;sslPassword = [value]&lt;BR /&gt;&lt;BR /&gt;I decrypted the value using&amp;nbsp;&lt;BR /&gt;$SPLUNK_HOME/bin/splunk show-decrypted --value '&amp;lt;encrypted_value&amp;gt;'&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Unfortunately it is giving me this error&lt;BR /&gt;139750988822336:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:crypto/evp/evp_enc.c:603:&lt;BR /&gt;139750988822336:error:0906A065:PEM routines:PEM_do_header:bad decrypt:crypto/pem/pem_lib.c:461:&lt;/P&gt;&lt;P&gt;A bad decrypt. What do you think did I miss? I am doubting the ssl password. But if this is the right step I need to try again and see how it goes.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2025 16:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741218#M3660</guid>
      <dc:creator>Paaattt</dc:creator>
      <dc:date>2025-03-08T16:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741224#M3661</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234516"&gt;@Paaattt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you able to get the password from the UF App downloaded from Splunk Cloud, rather than from a running Splunk instance?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are trying to decrypt the value in a running instance, does it start $7? (If so you should be able to use the&amp;nbsp;&lt;SPAN&gt;show-decrypted command - but remember to quote it so it doesnt try and resolve a variable starting $)&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME/bin/splunk show-decrypted --value '&amp;lt;encrypted_value&amp;gt;'&lt;/LI-CODE&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Mar 2025 08:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741224#M3661</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-09T08:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741225#M3662</link>
      <description>&lt;P class="lia-align-left"&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;. Looks like I am decrypting it wrong. Need to ad '' as prefix and suffix. All good now. Thank you!!!&lt;/P&gt;</description>
      <pubDate>Sun, 09 Mar 2025 08:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741225#M3662</guid>
      <dc:creator>Paaattt</dc:creator>
      <dc:date>2025-03-09T08:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741251#M3663</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I just have another question. The certificate works and we are now doing the ingestion. Thank you for that. On the Admin guide. I have to do the following on Splunk Cloud:&lt;/P&gt;&lt;P&gt;1. Create Index&lt;BR /&gt;2. Enable receiver 9997&lt;BR /&gt;3. Enable TCP Inputs 514&lt;BR /&gt;&lt;BR /&gt;We got a blocker on TCP Inputs. Ideally should be easy as like Settings &amp;gt; Data Inputs &amp;gt; Forwarded Inputs &amp;gt; TCP on the HF. But our approach is on Splunk Cloud (We don't use HF on this data even if we have for others. Project decided to have a saas to saas integration for KW). Now the prompt looks like this&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;"You currently don't have any forward&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt;ers installed. If you've recently installed a new forwarder, click the refresh button below to reload page."&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Refreshing it does nothing.&lt;BR /&gt;While I understand this on an on-prem deployment perspective. I can't fully understand the project's approach. the Admin guide provided as well is not helpful. No troubleshooting part for Splunk Cloud.&lt;BR /&gt;&lt;BR /&gt;How did you proceed on the ingestion piece?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 03:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/741251#M3663</guid>
      <dc:creator>Paaattt</dc:creator>
      <dc:date>2025-03-10T03:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud Kiteworks integration</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/755192#M4045</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234516"&gt;@Paaattt&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Recently I have onboarded the Kiteworks logs using inbuilt Kiteworks syslog mechanism to forward the logs to Syslog server. There is no option to select the log category, it will just send all the logs to Syslog server. So, my question is how can we make those logs CIM compliant and map it o Splunk data models. Currently there is only one single App(Kiteworks CISO dashboard app) is available and it doesn't contain any props.conf for log extractions.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;How did you manage those logs to map it to Splunk data models? could you please help here?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 05:18:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SplunkCloud-Kiteworks-integration/m-p/755192#M4045</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2025-11-05T05:18:42Z</dc:date>
    </item>
  </channel>
</rss>

