The CloudKnox App for Splunk builds a dashboard from the data provided by CloudKnox Add-on for Splunk.
No special steps are required to upgrade the CloudKnox App for Splunk from version 1.0.0 to version 1.1.0.
This app has been distributed in two parts.
This app can be set up in two ways:
CloudKnox App for Splunk can be installed through UI using "Manage Apps" > "Install app from file" or by extracting tarball directly into $SPLUNK_HOME/etc/apps/ folder.
Follow the below steps to configure the macros:
cloudknox(2)macro from the shown table.
index="main" sourcetype="cloudknox:$authSystemtype$:$category$". Update the definition with the index you used for data collection and save the configurations. For example:
cloudknoxindexmacro and repeat the above step. The user is required to configure this macro in order to user the "cloudknox_super_identities_alert".
cloudknox_url_without_schememacro and replace "xyz.cloudknox.io" with the URL of your CloudKnox instance. The user is required to configure this macro in order to use the drill-down functionality in the "CloudKnox Alerts" dashboard.
Note: If the user has selected a default index (Note: By default, Splunk considers only
main index as default index) in "Data Input" configuration during CloudKnox Add-on for Splunk's configuration step, then no need to perform steps 3, 4 and 5.
This App contains below 2 schedule searches:
cloudknox_super_identities_snapshot: This savedsearch updates cloudknox_si_snapshot KV store lookup to contain the latest super identities.
cloudknox_super_identities_alert: This alert is generated when any new super identity is added.
Configuring savedsearches is only required if the user wishes to use "cloudknox_super_identities_alert" which triggers an alert when a new super identity is indexed in Splunk. Follow the below steps to configure the savedsearches:
cloudknox(2)macro. Also you can verify if the data is there in the index by running the search query
Note: $SPLUNK_HOME denotes the path where Splunk is installed. Ex: /opt/splunk
* Added support for CloudKnox platform audit logs
* Added support for CloudKnox alerts
* Added alert that triggers when a new super identity is indexed in Splunk
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.