All Apps and Add-ons

What is the best practice to ingest Cloud Ironport logs to Splunk Cloud without sending them to On-Prem Syslog server?

kiran331
Builder

What is the best practice to ingest Cloud Ironport logs to Splunk Cloud without sending them to On-Prem Syslog server?

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi kiran331

I think you can use the Splunk Add-on for Cisco WSA to ingest Ironport logs. The add-on allows a Splunk software administrator to collect Cisco Web Security Appliance (WSA) access and L4TM log data.

https://splunkbase.splunk.com/app/1747
http://docs.splunk.com/Documentation/AddOns/latest/CiscoWSA/About

Hope this helps. Thanks!
Hunter

0 Karma

kiran331
Builder

Do we need a Heavy Forwarder in cloud? or there is other way to send logs to splunk cloud?

0 Karma

goodsellt
Contributor

Kiran, based on my knowledge of Splunk Cloud, you'll have to pass them through on on prem Heavy Forwarder or Universal forwarder where you can send data over UDP and/or SCP. Since the forwarders that connect to Splunk Cloud use SSL certs, it's safe to say you'll be unable to do a "direct" input to Splunk Cloud.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...