All Apps and Add-ons

DUO Log Add-on for Splunk setup

New Member

After installing the Duo Add-on i am not seeing "DUO Security 2fa logs" in data inputs. Is this compatible with version 6.4? Are there any special instructions after the app has been installed to get it to show up?

0 Karma
1 Solution

Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

View solution in original post

0 Karma

Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

View solution in original post

0 Karma

New Member

Found it. Testing it out now.

Thanks for your help

0 Karma

Path Finder

Where did you find it? I am not seeing it and that URL doesn't work on 6.5.

0 Karma

New Member

Is it under Scripts? Under data inputs what "type" would it be under?

0 Karma

Path Finder

It should be it's own type, "DUO Security 2fa logs" in the Local section.

screenshot

0 Karma

Path Finder

You should also be able to find it under the "Add Data" dialog;
try appending this path to your Splunk server's url:
"en-US/manager/TA-DUOSecurity2FA/adddata/selectsource?input_mode=1"

0 Karma