All Apps and Add-ons

How to link Aruba Central (logs, reporting etcc) to Splunk server?

anandnagarajan
New Member

Has anyone linked Aruba Central(logs, reporting etcc) to splunk server?
i was told Webhook was one option.

Tags (2)
0 Karma

alphiapj
Engager

I've been trying to get this to work as well.

Not sure if you had any luck.

I have created a HEC instance and tested it.

I created a webhook, but unsure of the URL to correctly add.  I simply get HTTP 500 status when I test the aruba webhook.

I'm sure there is a better way to setup the URL on the aruba side so it correctly sends data to inject.

0 Karma

manuel
New Member

Did you finally integrate Aruba Central via HEC?

0 Karma

alphiapj
Engager

I did get it to work. Much trial and effort as it was my first experience at HEC and webhooks.

This was the correct URL I figured for the Aruba central to send to my HEC.

https://<HEC URL>:8088/services/collector/raw?token=<your token>

chadmedeiros
Path Finder

yeah... just be aware that the token will show up in any tool that logs web traffic, since it is just plaintext in the url

Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...