We need to onboard Honeypot in our Splunk ES Instance, Can you Please help how we can Proceed further.
Also I can see there is canary app and add on https://help.canary.tools/hc/en-gb/articles/360002432418-Installing-the-Canary-Splunk-App-and-Add-on
Is this fine approach?Please suggest
@richgalloway can you please suggest
We have finalized the canary app , but only challenge we are facing Canary app is compatible with Splunk Cloud but the Canary addon is not compatible with Splunk Cloud as well as with the existing version of Splunk Enterprise(HF). can we wait till the splunk fixes up issues for the new version?
Can you Please suggest a way to move forward.
The Canary apps claim to compatible with Splunk 8.1, but, as you said, are not available for Splunk Cloud. Since they are not Splunk-supported apps, the best you can do is contact the developer or fix them yourself.
I can see there is one moreapp honeypy, let us know if it works and where we can install on SPlunk cloud or our IDM server
I've never used that app so I don't know if it works or not. Try installing it on your test Splunk to see if it works for you. If it does then request it be installed on your IDM.
Keep in mind that add-ons which cannot be installed on Splunk Cloud usually can be installed on an on-prem Heavy Forwarder which then sends the data to Splunk Cloud.
I can see there is one more honeypy, let us know if it works and where we can install on SPlunk cloud?
We have finalized the canary app , but only challenge we are facing Canary app is compatible with Splunk Cloud but the Canary addon is not compatible with Splunk Cloud as well as with the existing version of Splunk Enterprise(HF). can we wait till the splunk fixes up issues for the new version?
Can you Please suggest a way to move forward.
There are a few ways to onboard data into Splunk.
There may be other options if the service in question is in the cloud.
What is it you wish to do with Canary?