All Apps and Add-ons

What are Best Practices for WS WAF Integration?

rayar
Contributor

We are going to integrate WAF logs from AWS SQS

what is the best way to do it  ?

 

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

are you working on Splunk Cloud or Splunk Enterprise?

if you're working on Splunk Cloud you have two ways:

in the above links you have detailed step by step instructions.

If instead you're working on Splunk Enterprise, you can use only TA_AWS.

Anyway, I configured them few days ago and I can say that it's very easy!

Ciao.

Giuseppe

View solution in original post

rayar
Contributor

Hi

we are working on Splunk Enterprise , do you mean  ? 

https://splunkbase.splunk.com/app/1274/

what source type your used  ?

also I see that they have announced an End of Life plan for Splunk App for AWS 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

you have to use TA_AWS that isn't in EoL to ingest data.

This app gives you all the ingesting and parsing data structures, you have only to follow the instructions at the documentation link I shared and you haven't any problem about sourcetype, parsing etc...

About App for AWS, yes it's in EoL but there is a new App "Splunk App for AWs Security Dashboard" (https://splunkbase.splunk.com/app/6311/) that replace the old one.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

are you working on Splunk Cloud or Splunk Enterprise?

if you're working on Splunk Cloud you have two ways:

in the above links you have detailed step by step instructions.

If instead you're working on Splunk Enterprise, you can use only TA_AWS.

Anyway, I configured them few days ago and I can say that it's very easy!

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

good for you, see next time.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...