Splunk Enterprise
You need to configure Splunk Enterprise to receive events from either the Splunk Universal Forwarder or the Splunk DB Connect application.
Prerequisites
- Splunk Enterprise is installed
- Appropriate access to the system is in place
- You are familiar with the Splunk interface
Splunk DB Connect is an application from Splunk Enterprise you can install in your Splunk Enterprise instance. Splunk DB Connect retrieves events from the database you define, such as BeyondTrust Endpoint Privilege Management Reporting, and inserts the events into Splunk Enterprise.
You can use Splunk DB Connect to query the Export Views for Endpoint Privilege Management.
You can use SQL authentication or any of the default Endpoint Privilege Management Reporting accounts to authenticate with the BeyondTrust database. The default accounts are Report Reader, Event Parser, and Data Admin.
You can retrieve events from your endpoints or your Windows event collector node instead.
For more information, see the following:
Install DB Connect
Prerequisites
- Splunk Enterprise 6.4.0 or later
- Java Platform, Standard Edition Development Kit (JDK) from Oracle. JDK is required. The JRE alone is not sufficient.
- Java Database Connection (JDBC) to connect to databases
For more information, see the following:
Install on Splunk Enterprise
- Open your Splunk Enterprise instance, and click App: Search & Reporting from the top menu bar.
- If DB Connect is installed, it appears in the list. Otherwise, click Find More Apps.
- Type DB Connect in the search box if Splunk can connect to the internet. Follow the onscreen instructions to install DB Connection. Alternatively, you can download DB Connect from the Splunk store to install manually.
Note
To download DB Connect from the Splunk store, see https://splunkbase.splunk.com/app/2686/. This page requires email verification.
- Click App: Search & Reporting > Manage Apps to install DB Connect from a separate installer.
- Click Install app from file and browse to the location of DB Connect you downloaded.
- Click Upload and follow the onscreen instructions to install DB Connect.
- After DB Connect is installed, you can access it from the App: Search & Reporting top menu.
Configure Splunk Enterprise to receive events
- Click Settings > Forwarding Receiving (under the Data menu).
- Click Configure Receiving and then New to create an entry.
- Enter 9997 in the Listen on this port field.
- Click Save.
Splunk Enterprise is now configured to listen for events sent using any method.
Updated 3 days ago