SIEM Integration - Splunk HEC

This article will cover how to set up the integration with Splunk and your Sharetru platform.

Splunk HEC setup

Note: Do not toggle the Enable to "on" until you have filled out the form illustrated below and completed a test of the connection.
Use the SIEM "Select Service..." dropdown and select the Splunk HEC service:
image-20240711-215412

image-20240711-215603

You should now see the available options for setting up your Splunk integration.
image-20240711-220534
The only format available for Splunk HEC is JSON.
image-20240711-210337

To view an example of the SIEM test message click the link button.
image-20240711-211547

Enter the Hostname or IP and port for your Splunk instance.

image-20240711-210009
Enter the path to the endpoint:
image-20240711-210503

Enter the Authentication token from your Splunk HEC configuration.
image-20240711-210756

Enable the option to use a signed SSL certificate or disable to use a self-signed SSL certificate:
image-20240711-210946
Click "Save".
image-20240531-173832

Click "Test Connection" to send event to your Splunk instance.

 image-20240531-173905

If the connection is successful you will receive a message verifying that result.
siemtestsuccess

*You should verify that the message was received by your Splunk HEC instance. *

However, if the connection is not successful you will receive a message regarding the failure. 

Upon successfully completing the test you may toggle the "Enable" switch on and then click "Save".

This will finalize the SIEM integration set up.

image-20240715-203324
image-20240716-181939