Monitoring Splunk

Issue with Security Command Center Logs Not Appearing in Splunk

AL3Z
Builder

Hi,


We set up Security Command Center to send alerts to Splunk for detecting mining activity. However, I've observed that we're not receiving SCC logs in Splunk at the moment. What steps can we take to resolve this issue?

Thanks

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

How are you getting SCC events into Splunk?  Are you using the add-on (https://splunkbase.splunk.com/app/6426)?

Have you seen the docs at https://cloud.google.com/security-command-center/docs/how-to-configure-scc-splunk?

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

How are you getting SCC events into Splunk?  Are you using the add-on (https://splunkbase.splunk.com/app/6426)?

Have you seen the docs at https://cloud.google.com/security-command-center/docs/how-to-configure-scc-splunk?

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...