Requirements:
- Log ingestion via the Cisco AMP link below:
Data can be consumed via bunny
ConsumeAMQP professor for Apache NiFi
Installation:
Splunk Cloud Victoria Experience (non-ES) - ingestion via HTTP Event Collector (HEC):
- The CCX Add-on for Cisco Secure Endpoint should be installed on the AdHoc Search Head (default sourcetype - cisco:secureendpoint).
Splunk Cloud Victoria Experience (ES) - ingestion via HTTP Event Collector (HEC) configured on the AdHoc search head:
- The CCX Add-on for Cisco Secure Endpoint when installed on the AdHoc it is replicated by default to the ES Search Head (default sourcetype - cisco:secureendpoint).
Splunk Cloud Classic or Splunk Enterprise ingestion via HTTP Event Collector (HEC):
- The CCX Add-on for Cisco Secure Endpoint should be installed on Search Heads, and Forwarder (HF) (default sourcetype - cisco:secureendpoint).
*In case logs are forwarded via UF this Add-on should be installed on the IDXs (default sourcetype - cisco:secureendpoint).
Known issues:
- (none)
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.