Getting Data In

Splunk Integration for Crypto Object Discovery

Priyanka8440
New Member

Hello Team,
I am working on a requirement to discover cryptographic objects using Splunk. I need to collect relevant log data containing information such as TLS versions, ciphers, certificates, IPs, hosts, ports, and protocols.
Could you please suggest how this data can be collected and integrated into Splunk, and which log sources or Splunk are recommended?
Thank you!

Labels (2)
0 Karma

_Raj
Path Finder

Hi,

For cryptographic-object discovery in Splunk, I would prioritize the sources like this

     

Log source / Splunk product What you can collect
     Splunk Stream   TLS version, cipher, source/destination IP, ports, protocol, certificate/TLS metadata
F5 / Palo Alto / Fortinet / proxy / load balancer logsTLS versions, ciphers, certificates, client/server IPs, ports
Nginx / Apache / HAProxy / API Gateway logsTLS version, cipher, server name, client IP, certificate-related information
Windows Schannel Event LogsTLS/SSL and certificate events
Linux/OpenSSL certificate inventoryCertificate subject, issuer, expiry, algorithm, key length, fingerprint
Splunk Enterprise SecurityCertificates data model, dashboards, correlation/searching
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...