Getting Data In

How to ingest gitlab audit logs to Splunk?

aman35
Observer

Hi All, 

I am new to splunk. We are using splunkcloud and version 8.2. 

We are exploring how to ingest gitlab audit logs in splunk.

I checked gitlab project audit add on is not available in splunkcloud. I have tested HEC endpoints. For me my HEC working from curl https request. 

But I am clueless how can I ingest gitlab logs to splunk and keep this process realtime and automated.

Please suggest.

 

Thanks in advance.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Doesn't gitlab simply produce log files? So you could just install a Universal Forwarder and ingest local files?

Just asking, don't know gitlab.

0 Karma

aman35
Observer

It does produce the log files.. But I never tried forwarder and ingestion. Can you please shed some light on it.

It will be great help if I can get some documentation about it. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

https://docs.splunk.com/Documentation/Splunk/latest/Data/Getstartedwithgettingdatain

---
If this reply helps you, Karma would be appreciated.
0 Karma

aman35
Observer

thank you @ricm @PickleRick . 

But I think splunkcloud does not use forwarders. it use IDM. we are using gitlab saas

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Cloud uses forwarders and IDM.  IDMs are not available for all stacks.  However, all Splunk Cloud customers can use forwarders to get data from their on-prem servers to Splunk Cloud.

To get data from another cloud service, you can use an IDM (if available) or an input on your Cloud search head (if on the Victoria experience) or a on-prem heavy forwarder.  Using the IDM requires asking Splunk Support to install an appropriate app for you.  The other solutions are self-service.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Roy_9
Motivator

@aman35 you could poll the data using REST API by building a custom-addon using splunk add-on builder or if these logs are writing to a file, you could monitor/read it by installing a splunk agent .

Coming to splunk cloud, splunk cloud SH provides universal forwarder crdentials package..

If you are using UF approach, you need to download these credentials and place it on the splunk UF @/opt/splunkforwarder/etc/apps location and create a gitlab app with inputs.conf and deploy it to the same location and perform a splunk restart.

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...