Splunk
  • 3 Minutes To Read
  • Print
  • Share
  • Dark
    Light

Splunk

  • Print
  • Share
  • Dark
    Light

Splunk captures, indexes, and correlates real-time data in a searchable repository.

Parameters

  1. Host Name (required) - The hostname of the Splunk server.
  2. Port (required) - Specify the port of the Splunk system. It is recommended to use TCP port 8089. For more details, see Splunk Docs - Securing Splunk Enterprise.
  3. Protocol (required, default: HTTPS) - Select between HTTP and HTTPS protocols when using to the specific adapter connection.
  4. User Name and Password (required) - The user name and password for an account that has read access to the API. To create a new user with read permissions., follow the tutorial in the official Splunk documentation.
  5. API Token (optional, default: empty) - API token can be used instead of user name and password.
  6. For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.

image.png

Advanced Settings

  1. Splunk search macros list (Optional, default: empty) - Specify a comma-separated list of Splunk search macros names. For details on Splunk search macros, see Splunk Knowledge Manager Manual - Define search macros in Settings.
    • Axonius will run the Splunk search macros names and will consider the results as if those were received from a CSV file. This means the search macros must include at least one column of required data as specified in the CSV adapter - Which fields will be imported with a devices file?.
    • If supplied, all connections for this adapter will run the specified search macros and will fetch devices from the results.
    • If not supplied, all connections for this adapter will not include any search macros results in the fetched data.
  2. Splunk installed software search macros list (Optional, default: empty) - Specify a comma-separated list of Splunk search macro names that provide installed software information. For details on Splunk search macros, see Splunk Knowledge Manager Manual - Define search macros in Settings.
    • Axonius will run the Splunk search macros names and will consider the results as if those were received from a CSV file with installed software information. This means the search macros must include at least one column of required data as specified in the Which fields will be imported with a software applications file?.
    • If supplied, all connections for this adapter will run the specified search macros and will fetch installed software from the results and associate them to device entities.
    • If not supplied, all connections for this adapter will not include any search macros results in the fetched data.
  3. Number of days to fetch (required, default: 30) - Specify the query size by number of days Axonius will request to fetch data from all the connections of this adapter.
  4. Maximum amount of records per search (required, default: 100000) - Specify the maximum number of records Axonius should fetch from all the connections of this adapter.
  5. Windows login fetch hours (required, default: 3) - Specify the Windows login data query size by hours Axonius will request to fetch from all the connections of this adapter.
  6. Fetch devices from the splunk-nexpose plugin (required, default: False)
    • If enabled, all connections for this adapter will fetch the devices data from splunk-nexpose plugin.
    • If disabled, all connections for this adapter will not fetch the devices data from splunk-nexpose plugin.
  7. Fetch devices from Cisco (required, default: True)
    • If enabled, all connections for this adapter will fetch the devices data from Cisco data in Splunk.
    • If disabled, all connections for this adapter will not fetch the devices data from Cisco data in Splunk.
  8. Fetch Splunk agent version (required, default: False) - Select whether to fetch information about the Splunk agent version.
    • If enabled, all connections for this adapter will fetchinformation about the Splunk agent version.
    • If disabled, all connections for this adapter will not fetch information about the Splunk agent version.

image.png

NOTE

For details on general advanced settings under the Adapter Configuration tab, see Adapter Advanced Settings.

Was This Article Helpful?