Hi,
I have a question on Netskope onboarding to Splunk.
I installed to TA-NetSkopeAppForSplunk (4.1.0) on Splunk cloud and configured the API tokens provided by Netskope, and logs are flowing.
However, the same add-on and tokens are configured on Splunk Enterprise (Intermediate Heavy Forwarder), and logs are not arriving. I tried using multiple local Splunk Enterprise instances for testing, and no logs.
Any recommendations on what could be the issue with the Enterprise version while it is working fine on Cloud?
Hi @tech_g706
I think the first thing you need to establish is whether you are able to connect to Netskope from your HF on premise.
Then also check your internal logs to see if there were any errors around the collection of these events.
If it looks like the events are collecting then you need to work out why the data is not sending from that forwarder to your indexers.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Thanks,
Upon checking the logs, it seems MongoDB is not running on the heavy forwarder, and that would be required.
Hi @tech_g706
I think the first thing you need to establish is whether you are able to connect to Netskope from your HF on premise.
Then also check your internal logs to see if there were any errors around the collection of these events.
If it looks like the events are collecting then you need to work out why the data is not sending from that forwarder to your indexers.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing