All Apps and Add-ons

Duo's Splunk Connector support for Admin API v2 handlers for authentication logs?

lim2
Communicator

It seems that the version 1.1.8 from Feb. 6, 2021still does not support Admin API v2 handlers for authentication logs according to URL:

Does Duo's Splunk Connector support Admin API v2 handlers for authentication logs? 

Are we supposed to use http://github.com/duosecurity/duo_log_sync/  to send to Splunk SIEM on 9997? But it seems that config.yml does not support sslPassword needed to write the logs to Splunk indexers?
Could duo_splunkapp/bin/lib/duo_client 's files (client.py at version 4.1.0) be upgraded to the same version as the ones in duo_client-4.3.0-py3.7.egg/duo_client/client.py at version 4.3.0 ?
Any other options or inputs?

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...