Getting Data In

I am looking to integrate Avanan

clintonburnett
Explorer

I am looking to integrate Avanan a phishing solution and send its security logs that are in JSON format to an on prem indexer. The phishing solution is in the cloud what is the best way to connect the two?

0 Karma
1 Solution

clintonburnett
Explorer

I moved on to another job before integrating though now Avanan has put out more documentation and gone through a few software updates. The documents are now public. The relevant information to integrate can be found here. Avanan published a two part guide. Then the integration in Splunk would be with the Splunk AWS app or similar if using Splunk cloud.

https://www.avanan.com/manuals/splunk-integration-part-one
https://www.avanan.com/manuals/splunk-integration-part-two
https://splunkbase.splunk.com/app/1274/

View solution in original post

0 Karma

clintonburnett
Explorer

I moved on to another job before integrating though now Avanan has put out more documentation and gone through a few software updates. The documents are now public. The relevant information to integrate can be found here. Avanan published a two part guide. Then the integration in Splunk would be with the Splunk AWS app or similar if using Splunk cloud.

https://www.avanan.com/manuals/splunk-integration-part-one
https://www.avanan.com/manuals/splunk-integration-part-two
https://splunkbase.splunk.com/app/1274/

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Avanan claims to have an integration into Splunk, at least according to the screenshot on https://www.avanan.com/siem - check with their apparently non-public docs for hopefully more information.

Once you know what they recommend and aren't sure about it, feel free to post a question to verify if their approach is a good practice.

0 Karma

ccsfdave
Builder

@clintonburnett Did you ever find a solution to this? I was thinking of needing a UF in my DMZ to get the Avanan data or maybe an email box to receive scheduled "custom query" from Avanan. How did you accomplish this?

0 Karma

clintonburnett
Explorer

I moved on to another job before integrating though now Avanan has put out more documentation and gone through a few software updates. The documents are now public. The relevant information to integrate can be found here. Avanan published a two part guide. Then the integration in Splunk would be with the Splunk AWS app or similar if using Splunk cloud.

https://www.avanan.com/manuals/splunk-integration-part-one
https://www.avanan.com/manuals/splunk-integration-part-two
https://splunkbase.splunk.com/app/1274/

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

It's possible that Avanan is capable of sending to HEC - if so, you should be able to enter at least a host, port, and HEC token on their end. The screenshot I linked to doesn't display the "send to remote server" form for their Splunk integration and their docs aren't public, so no idea if true or not.

0 Karma

clintonburnett
Explorer

Avanan only has place to put the Splunk host and port not a place for token. after researching I believe they claim integration as if you have Splunk cloud you can use HEC but must be a cloud instance and use the query string method to authenticate to Splunk cloud.

http://dev.splunk.com/view/event-collector/SP-CAAAE6P#auth

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Sounds to me like an issue for your network team - "how to send data into my corporate network?" is nothing I can help you with, too many company-specific details and policies in place presumably.

0 Karma

clintonburnett
Explorer

understood was looking for the splunk piece believe it is Http event collector.

0 Karma

clintonburnett
Explorer

Their integration is having logs in JSON Formation and an app that has two fields hostname and port. Which I think is probably good enough, but I am missing how to get that over the internet to Splunk.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...