Axway API Gateway Add-on for Splunk provides lightweight field extractions for your Axway API Gateway data.
It is meant to be used with the Axway API Gateway App for Splunk.
1.0.0: October 2019
Traffic logs are JSON structured data which schema is documented here: https://docs.axway.com/bundle/APIGateway_762_AdministratorGuide_allOS_en_HTML5/page/Content/AdminGuideTopics/schema.html
Open logging should be enabled. Please refer to the following documentation: https://docs.axway.com/bundle/APIGateway_762_AdministratorGuide_allOS_en_HTML5/page/Content/AdminGuideTopics/admin_open_logging.htm
In our AWS setup, open logging data - group-2_instance-1_traffic.log - is monitored by a CloudWatch agent and pulled to a CloudWatch Log Group then pushed to Splunk HTTP Event Collector via Kinesis Firehose.
This Add-on should however work with more simple architectures and ingestion methods depending on your constraints (i.e. monitoring open logging directory with Splunk Universal Forwarder).
Install the Add-on on your Splunk platform.
For distributed environments, the Add-on needs to be deployed on the Search Head as well as on Indexer(s) or Heavy Forwarder depending on the ingress instance as it includes parsing configuration parameters.
Open logging data should be indexed under the sourcetype 'axway:apigateway:traffic:json'
If the data is ingested via HTTP Event Collector, you need to configure an HEC input:
[http://input name] index = index indexes = index sourcetype = axway:apigateway:traffic:json token = token useACK = 1
If the data is monitored using a Splunk Universal Forwarder, you need to configure a monitoring stanza:
[monitor:///INSTALL_DIR/apigateway/logs/group-*_instance-*_traffic.log] sourcetype = axway:apigateway:traffic:json index = index
Do not hesitate to check provided log sample to make sure your indexed data matches data used to build this Add-on.
This Add-on does not yet include field extractions or directions to ingest payload data.
- Initial release
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.