We would like to start working on Google integration with Splunk
is there any APP available with Dashboards and Reports we can install ?
I think we are going to use Splunk_TA_google-cloudplatform to integrate the data
Maybe worth looking at this app - https://splunkbase.splunk.com/app/5404/
Its a template with dashboards and reports that will help starting to work with GCP logs.
Maybe worth looking at this app - https://splunkbase.splunk.com/app/5404/
Its a template with dashboards and reports that will help starting to work with GCP logs.
hey i installed gcp application template for splunk(https://splunkbase.splunk.com/app/5404) and my splunk add on for GCP is configured (https://splunkbase.splunk.com/app/3088/)to collect data but after installing and checking macro as mentioned here (https://splunkbase.splunk.com/app/5404/#/details)the gcp application template dashboards are not populated. can you help me out?
sure, can help....first of all, can you help with:
1) can you confirm that audit logs / pub sub is ingested with sourcetype "google:gcp:pubsub:message".
2) can you confirm how you are ingesting logs, metrics and asset inventory
3) have you set indexed extractions to use faster tstats searches?