All Apps and Add-ons

Troubleshoot Cisco Duo integration for Splunk

pc1
Path Finder

I am using the Cisco Security Cloud integration in order to try and import my Duo logs into splunk enterprise (on prem). Following a plethora of directions, including Duo Splunk Connector guide I still cannot get it to work. No data goes through and it stays in a "Not Connected" status. 

So far, I have verified that:
- Admin API token has correct permissions
- Integration is configured with correct admin api info like secret key, integration key, api hostname, etc. 
- I am using the newest version of this app: Cisco Security Cloud 

 

Does anyone have any tips for helping troubleshoot this issue? I cannot seem to find any logs or anything to even get a more advanced error code than "Not Connected" when I am pretty sure it should be working. 

Labels (2)
0 Karma
1 Solution

pc1
Path Finder
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @pc1 

On your host with the inputs configured, do you see anything in $SPLUNK_HOME/var/log/splunk/splunkd.log relating to this input not running? Or is there a filename in the $SPLUNK_HOME/var/log/splunk/ relating to the app? What does this output when the modular input tries to run.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...