All Apps and Add-ons

Tealeaf and Splunk

hconsidine
Engager

Hi we are just starting a Proof of concept with Splunk so appreciate that I am totally new. We are looking to do some Splunk with Tealeaf data. Specifically, event data. We are having challenges Tealeaf's CEP (Complex Event Processing) to generate the file. Has anyone done this or have any advice? Thanks!

Tags (1)

gesman
Communicator

I currently using TeaLeaf data exports into Splunk mostly for Fraud investigation and security analytics purposes for big financial brokerage and banking client.

We setup regular hourly and daily cxConnect log data exports into Splunk and I also built a set of customized Splunk dashboards allowing to run very quick drilldown views, such as:

"show me all accounts there were accessed by this group of IP addresses" or:

"alert me when multiple accounts were accessed by the same IP / User Agent combo".

Above queries is not something TeaLeaf is capable of and so Splunk comes really handy as a custom security investigation dashboard solution.

I plan to write a detailed blog about possibilities of combining TeaLeaf with Splunk. If anyone is really interested in that - I can make it happen faster so more people will be able to share and benefit from this technology.

Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...