Getting Data In

data indexing on rapid7 app for Splunk enterprise

att35
Builder

Hi,

I am planning to install Splunk app for Rapid7 Nexpose. We use Nexpose Enterprise edition. While checking the app documentation, I could not locate information on whether it would be defining a new index for data from Nexpose. Does anyone has additional information on this?

Our splunk setup has Indexer and search head on different servers. Do I need to install the app on both(Indexer & search head)?
The reason I ask this question is because we would prefer the data to be indexed on Splunk indexer instance, but would still need the app on the search head as well to use the dashboards.

Thanks,
~ Abhi

0 Karma
1 Solution

JJCassidy_R7
Explorer

The application does not define a new index for Rapid7 data – this option is left to the user. It uses the ‘default’ index out of the box but most users change this after installation.

In terms of placement inside your environment you can install it on a single node or both. The application pulls pre-processed data from your Nexpose Console so load on your Splunk node is minimal (meaning installation on the search head alone should be fine).

If you don’t like the idea of your search head pulling and indexing data then you can install a copy of the application on the indexer and configure it to pull data from your Nexpose Console. A copy of the application can then be installed on the search head to just view the indexed data (obviously both will have to be configured to use the new index you are considering setting up).

View solution in original post

0 Karma

JJCassidy_R7
Explorer

The application does not define a new index for Rapid7 data – this option is left to the user. It uses the ‘default’ index out of the box but most users change this after installation.

In terms of placement inside your environment you can install it on a single node or both. The application pulls pre-processed data from your Nexpose Console so load on your Splunk node is minimal (meaning installation on the search head alone should be fine).

If you don’t like the idea of your search head pulling and indexing data then you can install a copy of the application on the indexer and configure it to pull data from your Nexpose Console. A copy of the application can then be installed on the search head to just view the indexed data (obviously both will have to be configured to use the new index you are considering setting up).

0 Karma

kcmngai
New Member

How to refer to a separate index instead of using the default index "main"? I have added the following in the "inputs.conf"

index = rapid7

The Splunk was restarted but it seems no event logged in the new index. Moreover, will the Nexpose dashboard refer all data from the new index? Any customisation would be needed on the dashboard layer? Thanks.

Kelvin

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...