All Apps and Add-ons

DUO Log Add-on for Splunk setup

SamAlo
New Member

After installing the Duo Add-on i am not seeing "DUO Security 2fa logs" in data inputs. Is this compatible with version 6.4? Are there any special instructions after the app has been installed to get it to show up?

0 Karma
1 Solution

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

View solution in original post

0 Karma

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

0 Karma

SamAlo
New Member

Found it. Testing it out now.

Thanks for your help

0 Karma

robert_miller
Path Finder

Where did you find it? I am not seeing it and that URL doesn't work on 6.5.

0 Karma

SamAlo
New Member

Is it under Scripts? Under data inputs what "type" would it be under?

0 Karma

bawood
Path Finder

It should be it's own type, "DUO Security 2fa logs" in the Local section.

screenshot

0 Karma

bawood
Path Finder

You should also be able to find it under the "Add Data" dialog;
try appending this path to your Splunk server's url:
"en-US/manager/TA-DUOSecurity2FA/adddata/selectsource?input_mode=1"

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...