All Apps and Add-ons

Troubleshoot Cisco Duo integration for Splunk

pc1
Path Finder

I am using the Cisco Security Cloud integration in order to try and import my Duo logs into splunk enterprise (on prem). Following a plethora of directions, including Duo Splunk Connector guide I still cannot get it to work. No data goes through and it stays in a "Not Connected" status. 

So far, I have verified that:
- Admin API token has correct permissions
- Integration is configured with correct admin api info like secret key, integration key, api hostname, etc. 
- I am using the newest version of this app: Cisco Security Cloud 

 

Does anyone have any tips for helping troubleshoot this issue? I cannot seem to find any logs or anything to even get a more advanced error code than "Not Connected" when I am pretty sure it should be working. 

Labels (2)
0 Karma
1 Solution

pc1
Path Finder
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @pc1 

On your host with the inputs configured, do you see anything in $SPLUNK_HOME/var/log/splunk/splunkd.log relating to this input not running? Or is there a filename in the $SPLUNK_HOME/var/log/splunk/ relating to the app? What does this output when the modular input tries to run.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...