Configure Secure Firewall App in Splunk
To ensure that the Splunk server is reachable to receive the events, configure the Cisco Secure Firewall App in Splunk.
Before you begin
Ensure that you have obtained a Splunk server license and a Cisco Security Cloud account.
Procedure
Step 1 | Download and install the Splunk server using the instructions provided in Splunk Enterprise Installation Manual. | ||
Step 2 | To install Splunk license, log in to your Splunk server's web interface. | ||
Step 3 | Go to . Use the license received by email.
| ||
Step 4 | Download Cisco Security Cloud from Splunkbase Apps. | ||
Step 5 | To install Cisco Security Cloud, log in to your Splunk server's web interface. | ||
Step 6 | Go to . | ||
Step 7 | Click Browse and select the downloaded application file and upload. | ||
Step 8 | To configure the server to receive the syslog events from the Firewall Threat Defense device, go to , and then click the Syslog tab.
|