We are trying to on-board Akamai logs to Splunk. Installed the add-on. Here it is asking for proxy server and proxy host. I am not sure what these means? Our splunk instances are hosted on AWS and instances are refreshed every 45 days due to compliance and these are not exposed to internet (internal). How to create and configure proxy server here? Please guide me
This is the app installed - https://splunkbase.splunk.com/app/4310
Do you have direct connectivity to your Akamai feed from the EC2 instance? If so you shouldnt need to configure a proxy. Please can you post a screenshot or link to where you are looking?
Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards
Will
@kiran_panchavat how and where to create proxy server for this requirement? Please let me know.
To set up a proxy, please contact the Network team, discuss your requirements with them, and proceed accordingly.
You can create your own proxy server using an EC2 instance. Here are the steps:
sudo yum update -ysudo yum install squid -y
sudo vi /etc/squid/squid.conf
acl splunk_subnet src 10.0.1.0/24http_access allow splunk_subnet
http_access deny all
http_port 3128
sudo systemctl start squidsudo systemctl enable squid
Proxy Server: A proxy server acts as an intermediary between your Splunk instance and an external service (like Akamai’s log delivery endpoints). It forwards requests from your internal network to the internet and relays responses back. This is critical in your case since your Splunk instances lack direct internet access.
Proxy Host: This is the specific hostname or IP address of the proxy server that Splunk will use to route its outbound traffic.