To configure the Splunk application, follow the steps below:
- Login to Apex Central web console, and go to Detections > Notifications > Notification Method Settings.
- In the Syslog Settings section, specify the following:
- Server IP address: Type the IPv4 or IPv6 address of the syslog server.
- Port: The the port number of the syslog server.
- Facility: Select the facility code.
- Click Save.
- Go to Detections > Notifications > Event Notifications.
- Select the Event type, then on the right pane, slide the switch to enable the notification for the events that you prefer.
- Configure the Notification Methods by clicking on the Event (e.g. Virus found - first and second actions unsuccessful).
- In the Notification Methods section, tick Syslog.
- Click Save.
- Login to the TMCM web console, and go to Notifications > Notification Method Settings.
- In the Syslog Settings section, specify the following:
- Server IP address: Type the IPv4 or IPv6 address of the syslog server.
- Port: The the port number of the syslog server.
- Facility: Select the facility code.
- Click Save.
- Go to Notification > Event Notifications.
- Select the Event type, then on the right pane, slide the switch to enable the notification for the events that you prefer.
- Configure the Notification Methods by clicking on the Event (e.g. Virus found - first and second actions unsuccessful).
- In the Notification Methods section, tick Syslog.
- Click Save.
- Login to the TMCM web console, and go to Administration > Event Center > General Event Settings.
- In the Syslog Settings section, specify the following:
- Server IP address: Type the IPv4 or IPv6 address of the syslog server.
- Server Port: The the port number of the syslog server.
- Facility: Select the facility code.
- Click Save.
- Go to Administration > Event Center > Event Notifications.
- Select the Event type, and tick the checkbox to enable the notification for the events that you prefer.
- Configure the Notification methods by clicking on the Recipients (e.g. Virus found - first and second actions unsuccessful).
- In the Notification methods section, tick Syslog.
- Click Save.
- Click Add data.
- Choose syslog.
- Choose Consume syslog over UDP.
- Set the communication port, and choose syslogas the source type list.
- Check the readiness of syslog:
- Choose Manage Inputs.
- Select UDP.
- Check the setting, the following values should be seen:
- UDP Port: 514
- Source Type: syslog
- From the APP menu, click Dashboard.
- Click Create New Dashboard.
- Provide a title of your preference (e.g. Top 20 Threats), then click Create Dashboard.
- Click Edit Source.
- Paste the XML codes into editor, then click Save.
A sample XML template can be downloaded here. This XML template is a sample and can be modified depending on what needs to be displayed on the dashboard that will be created.
- The new dashboard will read the TMCM logs and generate a panel similar to the image below: