-
Notifications
You must be signed in to change notification settings - Fork 0
Splunk Plugin
Karthik Kumar Viswanathan edited this page Aug 20, 2021
·
5 revisions
- Admin downloads Chainkit add-on from SplunkBase.
- OR Admin downloads zip file from secure Chainkit subdomain and installs the add-on
- Admin configures plugin in Splunk UI, enters their ChainKit Information
- Admin tells plugin, listen for events on Index
- Plugin is ready for User hardening of data to destination Index
- Plugin is configured to instead listen on TCP port 1234 than to messages on a Index/Query
- User sends logs over TCP, destination is Splunk-Host:1234
- The plugin now gets log messages, hardens them and sends it to Chainkit, and the hardened log message is seen on Splunk
Copyright Chainkit 2021 | www.chainkit.com | info@chainkit.com | Twitter | LinkedIn | Facebook
Command Line Interface
See it in action
White Papers
Blog