Getting Data In

Integration document for Cisco Cyber Vision with Splunk

doli
Splunk Employee
Splunk Employee

I am looking for a document to integrate Cisco cyber vision integration with Splunk. 

Labels (1)
0 Karma

kartik247
New Member

Hi @doli ,

This is Kartik from Cisco. Please send an email to cisco-cybervision-splunk@cisco.com and the team will share the document.

Thanks!

0 Karma

kiran_panchavat
Influencer

@doli 

1. Go to the add-on and configure 

*Account Name: Enter a unique name for this account.
*IP Address/Domain : Enter the IP Address of the Cisco Cyber Vision in format https://<ip address> or https://<domain-name> 
API Token : Enter API Token generated from Cyber Vision for above account.

If you have proxy, configure the proxy details. 

kiran_panchavat_0-1741776643154.png

kiran_panchavat_1-1741776721902.png

 

2. Create input 

Navigate to the inputs section and create a new input based on your requirements.

kiran_panchavat_2-1741776753496.png

kiran_panchavat_3-1741776773761.png

Note: 

  • Create an index for this data source to store incoming events.
  • Check and open the necessary firewall ports/rules for data ingestion.
  • Ensure communication between the data source and Splunk components.
  • If events are not visible after configuration, check the internal index (_internal)

For Splunk Clusters: 

  • Create the index on the Cluster Master (CM) and push it to the indexers.
  • Also, create the same index on the Heavy Forwarder (HF). 

 

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@doli 

There is no direct access to a specific document titled "Cisco Cyber Vision Integration with Splunk". Please follow this. 

Based on standard practices from the Cisco and Splunk : 


Install the Add-On: In Splunk, go to Apps > Manage Apps > Install App from File and upload the add-on package (.spl file) from Splunkbase.

Configure the Add-On: Navigate to the add-on’s configuration page in Splunk, where you’ll input your Cisco Cyber Vision API details (e.g., IP address of the Cyber Vision portal, API token generated from Cyber Vision). You may also specify proxy settings or custom CA certificates if needed.

Set Data Inputs: Define the time interval for data polling and the Splunk index to store the data.

Install the App: Install the Splunk App similarly and use its dashboards to visualize the data.

Syslog Option: Alternatively, configure Cyber Vision to send CEF syslog data to Splunk via TCP/UDP inputs (see the Cisco Catalyst Add-on for Splunk for syslog setup details).

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Influencer

@doli 

You can find the necessary documentation for integrating Cisco Cyber Vision with Splunk on Splunkbase. The Cisco Cyber Vision Splunk Add-On allows organizations to pull information from Cisco Cyber Vision using its RESTful API interface. This add-on helps configure and pull component information, vulnerabilities, activities, and events from Cyber Vision to be used with the Cyber Vision Splunk App. 

 

For detailed instructions and to download the add-on, you can visit the  Cisco Cyber Vision Splunk Add On | Splunkbase 

Cisco Security and Splunk SIEM - Cisco

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...