<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk KnowBe4 Integration in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/683953#M114162</link>
    <description>&lt;P&gt;According to the developer, it can be done with HEC:&lt;BR /&gt;&lt;A href="https://infosecwriteups.com/knowbe4-to-splunk-33c5bdd53e29" target="_blank"&gt;https://infosecwriteups.com/knowbe4-to-splunk-33c5bdd53e29&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2024 18:02:04 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2024-04-11T18:02:04Z</dc:date>
    <item>
      <title>Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/600891#M104722</link>
      <description>&lt;P&gt;I was wondering if any one has successfully onboard KnowBe4 data? I don't see a TA or App on Splunkbase.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 14:38:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/600891#M104722</guid>
      <dc:creator>BluFalcon</dc:creator>
      <dc:date>2022-06-07T14:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/683953#M114162</link>
      <description>&lt;P&gt;According to the developer, it can be done with HEC:&lt;BR /&gt;&lt;A href="https://infosecwriteups.com/knowbe4-to-splunk-33c5bdd53e29" target="_blank"&gt;https://infosecwriteups.com/knowbe4-to-splunk-33c5bdd53e29&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 18:02:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/683953#M114162</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2024-04-11T18:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760316#M120452</link>
      <description>&lt;P class="lia-align-justify"&gt;I tried the configuration mentioned in the document, but it doesn't seem to be working for me. Does anyone have any more updated documentation on how this can be done?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 10:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760316#M120452</guid>
      <dc:creator>anmolxmr</dc:creator>
      <dc:date>2026-04-20T10:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760320#M120453</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315405"&gt;@anmolxmr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May i know which step or what error you got,..&lt;/P&gt;&lt;P&gt;more the details and more better the replies/answers will be, thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 13:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760320#M120453</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-04-20T13:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760340#M120455</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;context - I am using Splunk Enterprise running 9.4.7 and my HF is running 9.2.6&lt;/P&gt;&lt;P&gt;1. Created the KnowBe4 HEC Token on Heavy Forwarder&lt;/P&gt;&lt;P&gt;2. Created the index on the CM and pushed to the indexer cluster&lt;/P&gt;&lt;P&gt;3. Checked the FW logs and found that FW is accepting events from KnowBe4 IPs&lt;/P&gt;&lt;P&gt;4. Setup the index, sourcetype and&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. Crafted a test HEC payload and sent to HF via localhost (the HF itself) and confirmed the events are being indexed to the "Default" index&lt;/P&gt;&lt;P&gt;6. Added the URL and necessary details to knowbe4 following the developer's document. (except for the Authorization parameter which I am unable to setup)&lt;/P&gt;&lt;P&gt;The missing items are as follows:&lt;/P&gt;&lt;P&gt;1. Haven't created the indexes.conf file on the HF, so I am unable to select the index from the drop-down within the HEC token settings on the UI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. On the KnowBe4 side when I try to add the Authorization parameter with value "Splunk &amp;lt;HEC TOKEN&amp;gt;", it gives me an error saying "This value is blacklisted". Raised a support case with KnowBe4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no ERROR or WARN log for any meaningful troubleshooting so I am unable to proceed further on this request. Raised a Splunk support ticket as well so that is in-progress as well.&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 01:10:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760340#M120455</guid>
      <dc:creator>anmolxmr</dc:creator>
      <dc:date>2026-04-21T01:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760354#M120456</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315405"&gt;@anmolxmr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The KnowBe4 side refuses to accept the Auth token value, raising a support case with KnowBe4 support (&lt;A href="https://support.knowbe4.com/hc/en-us/requests/new)" target="_blank" rel="noopener"&gt;https://support.knowbe4.com/hc/en-us/requests/new) &lt;/A&gt;&lt;BR /&gt;seems to be the better way to fix this.&lt;BR /&gt;&lt;BR /&gt;also, the guide seems to be misleading. They set the auth to Bearer Token, and add the Splunk token there - which makes no sense to me.&lt;BR /&gt;That will add a header called Authorization&amp;nbsp; with value Bearer yourHECtoken .&lt;BR /&gt;Then under custom headers, they add the same header again, but with the (proper) value of Splunk yourHECtoken . I would for sure set Auth to None, and see if that helps, thanks.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;----------------------------------------------------------------------------------------------&lt;BR /&gt;If this post or any post addressed your question, could you pls:&lt;BR /&gt;Give it karma to show appreciation&lt;/P&gt;&lt;P&gt;PS - As of Apr 2026, my Karma Given is 2290 and my Karma Received is 494, lets revamp the Karma Culture!&lt;BR /&gt;Thanks and best regards, Sekar&lt;BR /&gt;----------------------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 13:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760354#M120456</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-04-21T13:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760485#M120463</link>
      <description>&lt;P&gt;The integration still doesn't work. Getting the following error on the Heavy Forwarder where the connection has been made:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WARN HttpListenener [6454 HttpDedicatedIoThread-1] - Socket error from &amp;lt;Knowbe4 IP address&amp;gt; while idling: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca - please check the output of the `openssl verify` command for certificates involved; note that ig certificate validation is enabled (requireClientCert or sslVerifyServerCert set to "true"), the CA certificate and the server certificate should not have the same Common Name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 04:34:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760485#M120463</guid>
      <dc:creator>anmolxmr</dc:creator>
      <dc:date>2026-04-27T04:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760511#M120465</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315405"&gt;@anmolxmr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;may i know if you checked:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;`openssl verify` command for certificates involved&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;also there is a discussion about this issue on the Splunk Slack Channel, could you pls check:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://splunkcommunity.slack.com/archives/CDE623ETD/p1776776953119089" target="_blank"&gt;https://splunkcommunity.slack.com/archives/CDE623ETD/p1776776953119089&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------&lt;BR /&gt;If this post or any post addressed your question, could you pls:&lt;BR /&gt;Give it karma to show appreciation&lt;/P&gt;&lt;P&gt;PS - As of Apr 2026, my Karma Given is 2290 and my Karma Received is 494, lets revamp the Karma Culture!&lt;BR /&gt;Thanks and best regards, Sekar&lt;BR /&gt;----------------------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 00:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760511#M120465</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-04-28T00:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk KnowBe4 Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760512#M120466</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;thanks for your help. I've joined the Slack community and tried a recommendation from there as well with no success.&lt;/P&gt;&lt;P&gt;Since we are ingesting the logs from SaaS to on-prem, the issue is likely in the SSL cert validation. We have requested for a domain and associated SSL cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also scheduled a call with KnowBe4 support. Hopefully we are nearing resolution on this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 02:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-KnowBe4-Integration/m-p/760512#M120466</guid>
      <dc:creator>anmolxmr</dc:creator>
      <dc:date>2026-04-28T02:16:43Z</dc:date>
    </item>
  </channel>
</rss>

