Splunk Management Integration
Overview
Splunk Management Integration is used to integrate TAKAKRYPT with the Splunk platform so that logs and system activities can be sent automatically to a centralized monitoring environment. This integration leverages Splunk's HTTP Event Collector (HEC) to send log data in real time, so that system activities can be monitored and analyzed through the Splunk dashboard.
With this integration, administrators can collect logs from TAKAKRYPT together with data from other systems on a single platform, making it easier to perform operational monitoring, security analysis, activity auditing, and investigation of incidents that occur on the running system.
Splunk Management Integration Functions
Splunk Management Integration serves to:
- Send logs and events from TAKAKRYPT to the Splunk platform automatically.
- Provide integration between TAKAKRYPT and external monitoring systems.
- Support centralized log management through the Splunk dashboard.
- Provide activity data that can be used for operational and security analysis.
- Enable real-time monitoring of system activity.
Splunk Management Integration Uses
Splunk Management Integration is used to:
- Make it easier for operational teams to monitor system activity from a single platform.
- Assist the investigation process when disruptions or security incidents occur.
- Support audit needs through centralized storage of activity history.
- Facilitate the search and analysis of large volumes of logs.
- Provide better visibility into system activity and conditions.
Splunk Management Integration Configuration
When creating a Splunk Management Integration configuration, administrators need to complete the following information.
1. Status
Specifies the status of the Splunk integration on TAKAKRYPT.
If the status is enabled, the system will begin sending logs to Splunk based on the specified configuration. The Last Run information is used to display the last time logs were sent.
2. Host
Specifies the address of the Splunk server used as the destination for log delivery.
The value used can be either an IP address or the hostname of the Splunk server that has been configured to receive data through the HTTP Event Collector (HEC).
3. Port
Specifies the communication port used to connect TAKAKRYPT with the Splunk HEC service.
The port used must match the configuration applied on the Splunk server.
4. Use TLS
Specifies the use of an HTTPS connection for communication with Splunk.
If enabled, the log delivery process will use an encrypted protocol so that data is more secure during transmission.
5. Index
Specifies the name of the Index on Splunk that will be used as the storage location for logs from TAKAKRYPT.
All logs sent will be stored in the specified index, making them easier to manage and search through the Splunk dashboard.
6. Auth Token
Specifies the Authentication Token (HEC Token) used to authenticate to the Splunk service.
This token must match the token created in the HTTP Event Collector configuration in Splunk and must have access rights to send data to the specified index.
Test Connection
Used to test the connection to the Splunk server before the configuration is applied.
This feature helps ensure that the host address, port, authentication token, and TLS settings are correct so that the log delivery process can run properly.
Sync Logs
Used to manually synchronize logs to Splunk.
This feature can be used to ensure that the latest log data has been successfully sent to the Splunk platform without waiting for the next synchronization process.
How Splunk Management Integration Works
- The administrator fills in the Splunk connection information, which includes Host, Port, Index, and Authentication Token (HEC Token).
- The administrator determines whether communication uses TLS (HTTPS) to secure the log delivery process.
- Before the configuration is applied, the administrator can use the Test Connection feature to ensure that the connection to the Splunk server works properly.
- After the configuration is saved and the integration status is enabled, TAKAKRYPT will send activity logs to Splunk automatically through the HTTP Event Collector (HEC).
- The received logs will be stored in the specified Index and can be used for monitoring, auditing, security analysis, and troubleshooting through the Splunk platform.