All Apps and Add-ons

DenyAll Application Security Dashboard configure

ovp
New Member

Hi,

How to configure Splunk in Denyall.

I need to install at Denyall server and which path need to install?

Can i get the manual

0 Karma

desmondw_splunk
Splunk Employee
Splunk Employee

Hi,

It's good to install Splunk Enterprise on server separately from DenyAll server.
The path to install Splunk Enterprise can be default or changed during installation process.

After installation of DenyAll app into Splunk Enterprise, I'd highly recommend you to ensure the sysylog port 514 (UDP) is opened in Splunk server, as DenyAll server will send syslog events using port 514 (as I noticed that I can't changed the Port in DenyAll console).
The dashboard and events will not work in Splunk due to inability to open port 514 in Splunk server, especially on CentOS or Linux, due to inability to open port 514 if you run/start Splunk using non-root user.

All the best. Cheers !

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...