Hi
We have Victoria splunk cloud for our splunk environment and and AWS cloud for our linux environment.
we have deployed splunk using splunk cloud and like to ingest the inspector logs in to splunk.
if any one can share the tips be appreciated.
thanks
Yogesh Raj
Swaitchfly
Hi @yr,
at first you should check if AWS inspector logs is inside your AWS subscription.
Then you can use Data Manager or the Splunk Add-On for AWS (https://splunkbase.splunk.com/app/1876).
Here you can find a detailed instruction to use this last Add-On https://docs.splunk.com/Documentation/AddOns/released/AWS/Inspector
Ciao.
Giuseppe
Hi
Please find my response.
at first you should check if AWS inspector logs is inside your AWS subscription.
===> How do i confirm that ? and document link ? or tips please ?
Then you can use Data Manager or the Splunk Add-On for AWS (https://splunkbase.splunk.com/app/1876).
===> We have splunk add-on for aws installed. is that enough to move on ?
Here you can find a detailed instruction to use this last Add-On https://docs.splunk.com/Documentation/AddOns/released/AWS/Inspector
==> once above is reveal we can follow the instructions.
again thank you so much
Yogesh
Switchfly
Hi @yr,
about my first question, you have to verify in your AWS subscription which are the services you enabled, I suppose that you could check this in your AWS console or asking to your AWS Sales Representative.
Data Manager is a very easy interface to ingest Cloud data, but if you haven't you can use the Splunk Add-On for AWS.
About instructions, I gave you the link to use the above Add-On.
In this url, you can find how to configure the AWS instance and the Splunk Add-On.
Ciao.
Giuseppe
Hello,,
thank you for your quick reply.
Yes we already have enabled aws inspector v2 in our aws cloud and we see vulnerability notification they inspector for all instances, ECRs and services.
we also have installed splunk add-on for AWS.
please share the link to configure and ingest inspector data/log in to splunk.
Thank you