Configure Secure Firewall App in Splunk

To ensure that the Splunk server is reachable to receive the events, configure the Cisco Secure Firewall App in Splunk.

Before you begin

Ensure that you have obtained a Splunk server license and a Cisco Security Cloud account.

Procedure


Step 1

Download and install the Splunk server using the instructions provided in Splunk Enterprise Installation Manual.

Step 2

To install Splunk license, log in to your Splunk server's web interface.

Step 3

Go to Settings > Licensing > Add license. Use the license received by email.

Note

Make sure to restart Splunk to complete license registration.

Step 4

Download Cisco Security Cloud from Splunkbase Apps.

Step 5

To install Cisco Security Cloud, log in to your Splunk server's web interface.

Step 6

Go to Apps > Manage Apps > Install app from file.

Step 7

Click Browse and select the downloaded application file and upload.

Step 8

To configure the server to receive the syslog events from the Firewall Threat Defense device, go to Apps > Cisco Security Cloud > Secure Firewall > Configure Application, and then click the Syslog tab.

  • In the Input Name field, enter any name.

  • In the Input Type field, enter UDP or TCP.

    TLS is not supported in the Cisco Security Cloud application. Use rsyslog or syslog-ng to establish TLS on Splunk server. For detailed procedures, refer to Configure TLS on Splunk Server.

  • In the Port field, enter a value between 1025 and 65535. The default port is 514.

  • Leave the Host field blank. This will allow the Splunk to process events from any Firewall Threat Defense.

  • In the Source Type field, enter cisco:ftd:syslog.

  • In the Interval field, enter 600 seconds.