Getting Data In

Splunk Integration

devraajpandya11
New Member

How do i integrate my website hosted on AWS(ec2) with splunk?

Labels (4)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Depends on what do you want to "integrate". Do you want to collect events generated by your web app/web server? Do you want to collect metrics about your server? Do you want to embed reports from Splunk on your website? Do you want to be able to perform some action on your Splunk environment from your web app? Something else?

0 Karma

apietsch
Splunk Employee
Splunk Employee

Just collecting the logs is a great start.

If you want to collect technical metrics about user interaction you can use the RUM integration as well.

And depending what your backend looks like you could use the opensource OpenTelemetry libraries to instrument your backend application that processes your web application data. There is even a free and opensource Splunk distribution of OpenTelemetry (including the collector) available. 

---------------------
Chaos Smoother | Data Wrangler
0 Karma

deepakc
Builder

At a high Level:

 

  1. Think about what data you want from your website, is it OS logs Application logs, Security Logs etc and identify them.
  2. For those logs you want is there a Splunk TA - Search on Splunk Base. (This will help with the data integration and parse the data).
  3. Install a Universal Forwarder onto the Web Hosted Servers and monitor the logs or other methods are API and Splunk HEC.
  4. You may even have to use a Heavy Forwarder to collect the logs - this depends on the logs/data you want and your Splunk architecture.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...