<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need SailPoint data in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-SailPoint-data-in-Splunk/m-p/261507#M50206</link>
    <description>&lt;P&gt;SailPoint is our new Identity Governance application. I need to access SailPoint data from within Splunk. I'm not a Splunk admin at my company...but, I need to run searches that require data from SailPoint.&lt;/P&gt;

&lt;P&gt;Is there a Splunk connector into SailPoint? or would the SailPoint admins just need to provide data flat files for the Splunk team to configure them as data inputs into Splunk?&lt;/P&gt;

&lt;P&gt;TIA!&lt;BR /&gt;
Trista&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2016 18:52:24 GMT</pubDate>
    <dc:creator>tmaltizo</dc:creator>
    <dc:date>2016-03-24T18:52:24Z</dc:date>
    <item>
      <title>Need SailPoint data in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-SailPoint-data-in-Splunk/m-p/261507#M50206</link>
      <description>&lt;P&gt;SailPoint is our new Identity Governance application. I need to access SailPoint data from within Splunk. I'm not a Splunk admin at my company...but, I need to run searches that require data from SailPoint.&lt;/P&gt;

&lt;P&gt;Is there a Splunk connector into SailPoint? or would the SailPoint admins just need to provide data flat files for the Splunk team to configure them as data inputs into Splunk?&lt;/P&gt;

&lt;P&gt;TIA!&lt;BR /&gt;
Trista&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 18:52:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-SailPoint-data-in-Splunk/m-p/261507#M50206</guid>
      <dc:creator>tmaltizo</dc:creator>
      <dc:date>2016-03-24T18:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Need SailPoint data in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-SailPoint-data-in-Splunk/m-p/261508#M50207</link>
      <description>&lt;P&gt;Splunk does not need a connector for SailPoint. Flat log files are easy to ingest in Splunk. &lt;/P&gt;

&lt;P&gt;It is easiest if the log files&lt;BR /&gt;
 - are one-line-per-event OR have a clearly defined start/end for multi-line events&lt;BR /&gt;
 - have a timestamp for each event (even better if the timestamp includes the timezone)&lt;/P&gt;

&lt;P&gt;You can also train Splunk to identify the fields within the log files, but that is &lt;EM&gt;not&lt;/EM&gt; necessary to get started - you can do "field extraction" at any time. So there is no need for a connector or a schema in Splunk.&lt;/P&gt;

&lt;P&gt;If you have the ability to configure how SailPoint writes the log files, take a look at this web page for even more advice about what makes a "good" log file:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://dev.splunk.com/view/logging-best-practices/SP-CAAADP6"&gt;Logging Best Practices&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is a great quote from a related page in the docs: "Splunk doesn't care about the format or schema of your data—queries and searches can be ad-hoc, and your data can come from any textual source. "&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2016 23:02:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-SailPoint-data-in-Splunk/m-p/261508#M50207</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-03-28T23:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need SailPoint data in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-SailPoint-data-in-Splunk/m-p/261509#M50208</link>
      <description>&lt;P&gt;You can also leverage Splunk DB Connect - which is likely the preferred method to access this sort of data from SailPoint. SailPoint has a solution called "STI" or Simple Table Integration, ask your SailPoint SE for access to this SDK and it should allow you to set up an intermediate database and service that talks to SailPoint IdentityIQ for you. From there Splunk DB Connect can talk to this intermediate database so you can report on SailPoint information.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2686/"&gt;https://splunkbase.splunk.com/app/2686/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2016 23:33:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-SailPoint-data-in-Splunk/m-p/261509#M50208</guid>
      <dc:creator>kchamplin_splun</dc:creator>
      <dc:date>2016-03-28T23:33:29Z</dc:date>
    </item>
  </channel>
</rss>

