Integrate Splunk SIEM with Instant ID as a Service
Use the Splunk Add-on to Instant ID as a Service to automatically forward audit logs from your IntelliTrust account to your Splunk SIEM.
The IntelliTrust Splunk Add-On is located at https://splunkbase.splunk.com/app/4204.
Add Splunk Add-on to Instant ID as a Service
- Select Main Menu
> Resources > Applications. The Applications
page appears. - Click Add. The Add Applications page appears.
- Click Splunk Add-on. The Add Splunk Add-on page appears.
- In the Application Name field, type a name for your application.
- (Optional) In the Application Description field, type a description for your application.
- (Optional) Add a custom application logo as follows:
- Click Add
next to Application Logo. The Upload Logo dialog box appears. - Click Upload
to select an image file to upload. - Browse to select your file and click Open. The Upload Logo dialog box reappears showing your selected image.
- If required, resize your image.
- Click OK.
- Click Add
- Click Submit. The Complete page opens.
- Do one of the following:
- Click Copy to Clipboard to copy the credentials.
- Click Credentials to download a JSON file that contains the credentials
Attention: Once you leave this page the credentials are no longer available. If you do not copy or download the data then you will need to recreate the application.
- Click Done.
Add IntelliTrust Add-on to Splunk
- Log in to Splunk.
- Click Find More Apps.
- In the Browse More Apps field, search for IntelliTrust. The Entrust Datacard IntelliTrust Add-on for Splunk dialog box opens.
- Click Install.
- In the Login, page enter your Splunk.com username and password.
- Accept the terms of agreement.
- Click Login and Install.
- Click Restart Now on the Restart Splunk prompt.
- Click OK.
- Log in to Splunk as an administrator. The IntelliTrust Add-on appears in the Apps list.
- Click IntelliTrust Add-on. The Inputs page opens.
- Click Configuration. The Configuration page opens.
- Click Add-on Settings.
- In the IntelliTrust Splunk App Secret field, paste the credentials that you generated in Add Splunk add-on to Instant ID as a Service.
- Click Save.
- On the Inputs page, click Create New Input.
- In the Interval box enter the interval period, in seconds, that Splunk queries IntelliTrust for new audit events.
- In the Include field select the type of audits to include. Options include:
- Authentication Events Only
- Management Events Only
- Both
- Click Add.