All Apps and Add-ons

How to configure the Wazuh app to get data into Splunk?

TheBeaker
Engager

We have just started testing out Wazuh in our lab, and wanted to get that data Splunk'd.

It looks like the Wazuh App has a configuration entry for the Wazuh manager's API credentials. But the guide also states that a Forwarder be installed on the Wazuh manager:

https://documentation.wazuh.com/current/installation-guide/installing-splunk/splunk_forwarder.html

That seems redundant. Before I tear apart the bits to see how it works, can somebody clear this up for me?

Thanks!

0 Karma

wazuh
Explorer

Hello @TheBeaker,

It's needed to set up data forwarding and also a connection with the Wazuh API in order to the app can work properly. This is because the app currently works with two data sources. From the app, you can:

  • Visualize Wazuh indexed data and perform searches, so it's necessary to forward the alerts from the Wazuh manager to Splunk.
  • Get information and make use of the Wazuh API functionalities. For instance, get information about your cluster status, manage and configure your configuration groups and much more features in 'real time' are done just by requesting to the Wazuh API.

I hope that helps, you can join to the mailing list: https://groups.google.com/forum/#!forum/wazuh
or join to our community Slack channel: https://wazuh.com/community/join-us-on-slack/
Also, you can open an issue in our app repository: https://github.com/wazuh/wazuh-splunk.

Regards

0 Karma

rtrioux
New Member

Please read my question again. I think you may have answered someone else's question by accident, as it has nothing to do with my post. Thanks!

0 Karma

wazuh
Explorer

Got it! The answer was just edited.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...