All Apps and Add-ons

DenyAll Application Security Dashboard configure

ovp
New Member

Hi,

How to configure Splunk in Denyall.

I need to install at Denyall server and which path need to install?

Can i get the manual

0 Karma

desmondw_splunk
Splunk Employee
Splunk Employee

Hi,

It's good to install Splunk Enterprise on server separately from DenyAll server.
The path to install Splunk Enterprise can be default or changed during installation process.

After installation of DenyAll app into Splunk Enterprise, I'd highly recommend you to ensure the sysylog port 514 (UDP) is opened in Splunk server, as DenyAll server will send syslog events using port 514 (as I noticed that I can't changed the Port in DenyAll console).
The dashboard and events will not work in Splunk due to inability to open port 514 in Splunk server, especially on CentOS or Linux, due to inability to open port 514 if you run/start Splunk using non-root user.

All the best. Cheers !

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...