<< PREVIOUS                        NEXT >>

 

VIRSEC APP CONFIGURATION IN SPLUNK


 

Follow the below steps to install Virsec App in Splunk

  1. Virsec App is added to the Splunk App Store. Download the file virsec-security-platform-threat-dashboard_100.tgz from the URL: https://splunkbase.splunk.com/app/4143/

  2. Click Find More Apps

    Picture 12

  3. Navigate to Apps > Manage Apps

    Picture 13

  4. Click Install App from File

    Picture 14

  5. Upload the file virsec-security-platform-threat-dashboard_100.tgz from the local system. Click Upload

    Picture 15

  6. Click Restart Now to restart the splunk server

    Picture 16

  7. Click OK on the confirmation pop-up message

  8. Click OK to display the login page

  9. Log in to Splunk again with valid credentials

  10. Navigate to Apps > Splunk for Virsec

    Picture 18

  11. The below page is displayed

    Picture 19

  12. From VSP 2.9 onwards, Splunk can be configured with SSL being enabled or disabled

  13. Follow the below steps to enable or disable SSL on the Splunk server:

    1. Navigate to Settings > Data Inputs. Click HTTP Event Collector

    2. Click Global Settings

      Picture 22

    3. Enable or disable the checkbox Enable SSL as required

      Picture 23

  14. If a switch from HTTPs to HTTP is required:

    1. Disable the checkbox of Enable SSL on the Splunk server

    2. Delete the Splunk configuration from Administration > Configurations in CMS

    3. Add the below property in the file: /opt/virsec/cms/z-server/config/application.properties in the siem-splunk-service container:

      siem.splunk.config.event.collector.disable.certificate=true

       

    4. Restart the siem-splunk-service using the docker command:

      restart siem-splunk-service

       

    5. Reconfigure the Splunk information in CMS under Administration > Configurations

  15. During upgrade from lower versions to VSP 2.9 or Above, follow the below steps:

    1. Enable the checkbox of Enable SSL on the Splunk server

    2. Delete the Splunk configuration from Administration > Configurations in CMS

    3. Reconfigure the Splunk information in CMS

 

  << PREVIOUS                           NEXT >>