I noticed that "splunk" authentication does not show up in the Access Center or the Access Search views. What gives?
Splunk authentication messages live in the _audit index and are not searched on by default. To enable reporting of Splunk authentication to Access Protection views such as the Access Center do the following:
Place the following in, or add to: $SPLUNK_HOME/etc/apps/TA-splunk/local/eventtypes.conf
[splunk_access] search = "action=login attempt" NOT "action=search"
Place the following in, or add to: $SPLUNK_HOME/etc/apps/TA-splunk/local/tags.conf
[eventtype=splunk_access] authentication = enabled
Add index _audit to default search indexes on a per role basis
To enable Splunk authentication for admins and scheduled search:
Manager>>Access controls>>Roles>>admin>>Indexes searched by default>>Add>>_audit
To enable Splunk authentication for users (Warning: This gives the user role capability to search _audit index):
Manager>>Access controls>>Roles>>user>>Indexes searched by default>>Add>>_audit Manager>>Access controls>>Roles>>user>>Indexes>>Add>>_audit
To verify these steps you can perform the following search: "tag=authentication app=splunk"
Splunk authentication messages live in the _audit index and are not searched on by default. To enable reporting of Splunk authentication to Access Protection views such as the Access Center do the following:
Place the following in, or add to: $SPLUNK_HOME/etc/apps/TA-splunk/local/eventtypes.conf
[splunk_access] search = "action=login attempt" NOT "action=search"
Place the following in, or add to: $SPLUNK_HOME/etc/apps/TA-splunk/local/tags.conf
[eventtype=splunk_access] authentication = enabled
Add index _audit to default search indexes on a per role basis
To enable Splunk authentication for admins and scheduled search:
Manager>>Access controls>>Roles>>admin>>Indexes searched by default>>Add>>_audit
To enable Splunk authentication for users (Warning: This gives the user role capability to search _audit index):
Manager>>Access controls>>Roles>>user>>Indexes searched by default>>Add>>_audit Manager>>Access controls>>Roles>>user>>Indexes>>Add>>_audit
To verify these steps you can perform the following search: "tag=authentication app=splunk"