Disclaimer: This app is not created or managed by Lacework.
Set up with the Lacework Event add-on is a simple process that can be completed in just a few steps:
1. Install the add-on.
2. Under Configurations > Account, click Add.
3. In the window that appears, input the following and submit:
a. Account name: Your Lacework sub-domain (case-sensitive).
* This information can be found in your Lacework account. Example: https://tripadvisor.lacework.net --> tripadvisor is the domain.
b. Username: Your Lacework API Access Key ID
c. Password: Your Lacework API Secret Key
4. This Configuration account stores your Lacework account credentials, and it can be used with as many Input accounts you would like, which we will be adding in the next section.
5. Under Inputs, click Create New Input
6. Input the following:
* Name: Name of your input name, such as "DevOps Team Events"
* Interval: How often the inputshould be provided to the add-on. The add-on runs every 24 hours so an interval of 86400 seconds is recvommended.
* Index: The Splunk index to which you would like the data to be written to.
* Sub-domain: Your Lacework sub-domain (case-sensitive).
* Lacework App Account: Select your Configuration account that is associated with this Lacework unit.
* Bearer Token Expiration: How long the Lacework API token should remain active, in seconds.
7. And that is it! You have successfully set up the add-on. Depending on your interval input, you will begin to see Lacework event data in your specified indices.
Fixed bug where users could not link Input and Configuration accounts properly. Determined to be an issue with the data validation method in script.
Added improved data validation for user input and refactored Python script to increase readability.
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.