All Apps and Add-ons

DUO Log Add-on for Splunk setup

SamAlo
New Member

After installing the Duo Add-on i am not seeing "DUO Security 2fa logs" in data inputs. Is this compatible with version 6.4? Are there any special instructions after the app has been installed to get it to show up?

0 Karma
1 Solution

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

View solution in original post

0 Karma

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

0 Karma

SamAlo
New Member

Found it. Testing it out now.

Thanks for your help

0 Karma

robert_miller
Path Finder

Where did you find it? I am not seeing it and that URL doesn't work on 6.5.

0 Karma

SamAlo
New Member

Is it under Scripts? Under data inputs what "type" would it be under?

0 Karma

bawood
Path Finder

It should be it's own type, "DUO Security 2fa logs" in the Local section.

screenshot

0 Karma

bawood
Path Finder

You should also be able to find it under the "Add Data" dialog;
try appending this path to your Splunk server's url:
"en-US/manager/TA-DUOSecurity2FA/adddata/selectsource?input_mode=1"

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...