All Apps and Add-ons

Akamai logs to Splunk

splunklearner
Communicator

Anyone please help me how to get Akamai logs to Splunk. We have clustered environment with syslog server uf installed in it and forwards data to our Deployment Server initially and then it deployes to Cluster Manager and Deployer. We have 6 indexers with 2 indexers in each site (3 site multi cluster). 3 search heads one in each site. How to proceed with this?

Labels (2)
0 Karma

kiran_panchavat
Influencer

@splunklearner 

Please check the pre-requisites . https://techdocs.akamai.com/siem-integration/docs/siem-splunk-connector 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@splunklearnerIf you don't have a heavy forwarder and need to install the add-on, you can install it on the search head cluster. Please refer to the documentation below for more details and installation instructions.

Install an add-on in a distributed Splunk Enterprise deployment - Splunk Documentation

To deploy an add-on to the search head cluster members, use the deployer. https://docs.splunk.com/Documentation/Splunk/9.4.1/DistSearch/PropagateSHCconfigurationchanges 

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@splunklearner I recommend using the add-on. Akamai SIEM Integration | Splunkbase

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

kiran_panchavat
Influencer

@splunklearner   

Install the add-on on your heavy forwarder and configure it. You have two options for sending logs to Splunk:

  1. Install the add-on on your heavy forwarder and use it to send logs to Splunk.
  2. If Akamai supports syslog, you can send logs to your syslog forwarder, which will then forward them to Splunk. In this case, please configure syslog-ng or rsyslog to capture Akamai logs in a specific directory and create the necessary inputs to onboard the logs into Splunk.

Configure the UF on your syslog server to monitor the log files. Update the inputs.conf file to specify the log file paths and the outputs.conf file to forward the data to your indexe

Example inputs.conf:

[monitor:///var/log/akamai/*.log]
index = akamai
sourcetype = akamaisiem

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@splunklearner 

Please follow this SIEM Splunk connector

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

splunklearner
Communicator

I am stuck at this point --

Click the Akamai Security Incident Event Manager API.

I can't find this in data inputs after installing add-on.

0 Karma

kiran_panchavat
Influencer

@splunklearner 

Go to Settings > Data Inputs, where you will find the Akamai data input.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

splunklearner
Communicator

Not able to find.

0 Karma

kiran_panchavat
Influencer

@splunklearner 

 

Please verify the prerequisites. It's a Java issue, you need to make sure Splunk can access Java.  I can see some solutions that, they are able to see the data inputs using the below steps:

Fixed the issue by adding the config in inputs.conf"[TA-Akamai_SIEM]#disable the running introspection.

run_introspection=false

 

 

image.png

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Best Strategies to Optimize Observability Costs

 Join us on Tuesday, May 6, 2025, at 11 AM PDT / 2 PM EDT for an insightful session on optimizing ...

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...