All Apps and Add-ons

Akamai logs to Splunk

splunklearner
Communicator

Anyone please help me how to get Akamai logs to Splunk. We have clustered environment with syslog server uf installed in it and forwards data to our Deployment Server initially and then it deployes to Cluster Manager and Deployer. We have 6 indexers with 2 indexers in each site (3 site multi cluster). 3 search heads one in each site. How to proceed with this?

Labels (2)
0 Karma

kiran_panchavat
Influencer

@splunklearner 

Please check the pre-requisites . https://techdocs.akamai.com/siem-integration/docs/siem-splunk-connector 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@splunklearnerIf you don't have a heavy forwarder and need to install the add-on, you can install it on the search head cluster. Please refer to the documentation below for more details and installation instructions.

Install an add-on in a distributed Splunk Enterprise deployment - Splunk Documentation

To deploy an add-on to the search head cluster members, use the deployer. https://docs.splunk.com/Documentation/Splunk/9.4.1/DistSearch/PropagateSHCconfigurationchanges 

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@splunklearner I recommend using the add-on. Akamai SIEM Integration | Splunkbase

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

kiran_panchavat
Influencer

@splunklearner   

Install the add-on on your heavy forwarder and configure it. You have two options for sending logs to Splunk:

  1. Install the add-on on your heavy forwarder and use it to send logs to Splunk.
  2. If Akamai supports syslog, you can send logs to your syslog forwarder, which will then forward them to Splunk. In this case, please configure syslog-ng or rsyslog to capture Akamai logs in a specific directory and create the necessary inputs to onboard the logs into Splunk.

Configure the UF on your syslog server to monitor the log files. Update the inputs.conf file to specify the log file paths and the outputs.conf file to forward the data to your indexe

Example inputs.conf:

[monitor:///var/log/akamai/*.log]
index = akamai
sourcetype = akamaisiem

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@splunklearner 

Please follow this SIEM Splunk connector

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

splunklearner
Communicator

I am stuck at this point --

Click the Akamai Security Incident Event Manager API.

I can't find this in data inputs after installing add-on.

0 Karma

kiran_panchavat
Influencer

@splunklearner 

Go to Settings > Data Inputs, where you will find the Akamai data input.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

splunklearner
Communicator

Not able to find.

0 Karma

kiran_panchavat
Influencer

@splunklearner 

 

Please verify the prerequisites. It's a Java issue, you need to make sure Splunk can access Java.  I can see some solutions that, they are able to see the data inputs using the below steps:

Fixed the issue by adding the config in inputs.conf"[TA-Akamai_SIEM]#disable the running introspection.

run_introspection=false

 

 

image.png

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...