All Apps and Add-ons

DenyAll Application Security Dashboard configure

ovp
New Member

Hi,

How to configure Splunk in Denyall.

I need to install at Denyall server and which path need to install?

Can i get the manual

0 Karma

desmondw_splunk
Splunk Employee
Splunk Employee

Hi,

It's good to install Splunk Enterprise on server separately from DenyAll server.
The path to install Splunk Enterprise can be default or changed during installation process.

After installation of DenyAll app into Splunk Enterprise, I'd highly recommend you to ensure the sysylog port 514 (UDP) is opened in Splunk server, as DenyAll server will send syslog events using port 514 (as I noticed that I can't changed the Port in DenyAll console).
The dashboard and events will not work in Splunk due to inability to open port 514 in Splunk server, especially on CentOS or Linux, due to inability to open port 514 if you run/start Splunk using non-root user.

All the best. Cheers !

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...