Getting Data In

How do I go about the integration with Global Relay?

spl_aficionado
Path Finder

One of our clients is asking for a fresh integration with Global Relay as a replacement for ZL Archive, how do I go about it?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

More words please.

Most importantly - how does it relate to your customer's Splunk?

0 Karma

spl_aficionado
Path Finder

Hi @PickleRick

We would like to know how to integrate Global Relay with Splunk ingestion wise, determine what data and events need to be collected, and identify any connectivity requirements (internal vs. external hosting). I'm not sure whether Global Relay usually has an internal presence in the company or they are outside the company. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. For starters, I don't actually know either solutions (the ZL Archive mentioned before or the Global Relay) - just googled what they do.

But.

The main question is not what "needs to be collected", because that is something that should stem from the business needs. The question might be what can be collected. Either you build your business case from the business need and verify if it can be achieved with the service provider (in other words, your business says - we want to be able to track this and that and you verify if either of those providers give you means of retrieving such data) or you go the other way around - check what data you are able to ingest from there and verify if there is any business case for that.

A quick browse through their website doesn't yield very optimistic results. The only docs about any kind of API I could find was about sending data into their platform. I'm not sure if there is any way of either getting the data out of it or getting any form of automated query, retrieving audit records and so on. At least there's no easily available info on that. That might be a thing you need to contact their support about.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...