The Entrust Identity as a Service Add-on for Splunk enables centralizing your Identity as a Service authentication and management audit events in Splunk™ Enterprise and Splunk™ Cloud. The Identity as a Service Splunk Add-On is located at https://splunkbase.splunk.com/app/4204.
To integrate Splunk SIEM with Identity as a Service, you need to complete the following steps:
In
Identity as a Service, click
> Security > Applications.
The Applications page appears.
Click Add. The Select an Application Template page appears.
Do one of the following:
Select Identity as a Service Integrations from the search drop-down list and scroll to find the application you want to add to IDaaS.
- or -
In the Search bar, enter a search option to filter for the application you want to add to IDaaS.
Click Splunk Add-on. The Add Splunk Add-on page appears.
In the Application Name field, type a name for your application.
Optional. In the Application Description field, type a description for your application.
Optional. Add a custom application logo.Optional. Add a custom application logo.
Click
next
to Application Logo. The
Upload Logo dialog box appears.
Click
to select an image file to upload.
Browse to select your file and click Open. The Upload Logo dialog box reappears showing your selected image.
If required, resize your image.
Click OK.
Click Submit. The Setup page appears.
The Application ID is generated automatically.
Do one of the following:
Click Copy to Clipboard to copy the credentials generated by Identity as a Service.
-or-
Click Download to download a JSON file that contains the credentials needed to integrate with Splunk SIEM.
Attention: Once you leave this page the credentials are no longer available. If you do not copy or download the data then you will need to recreate the application.
Click Done.
Log in to Splunk.
Click Find More Apps.
In the Browse More Apps field, search for Identity as a Service. The Entrust Identity as a Service Add-on for Splunk dialog box appears.
Click Install.
In the Login, page enter your Splunk.com username and password.
Accept the terms of agreement.
Click Login and Install.
Click Restart Now on the Restart Splunk prompt.
Click OK.
Log in to Splunk as an administrator. The Identity as a Service Add-on appears in the Apps list.
Click Identity as a Service Add-on. The Inputs page appears.
Click Configuration. The Configuration page appears.
Click Add-on Settings.
In the Identity as a Service Splunk App Secret field, paste the contents that you generated in Step 1, Add Splunk add-on to Identity as a Service.
Click Save.
On the Inputs page, click Create New Input.
Under Action click Edit. The Update Identity as a Service dialog box appears.
In the Interval box enter the interval period, in seconds, that Splunk queries Identity as a Service for new audit events.
In the Include field select the type of audits you want to ingest. Options include:
Authentication Events Only
Management Events Only
Both
Click Add.