Export Audit Logs to Splunk
Aisera's Gen AI platform includes the functionality to export audit logs in real-time to Splunk. This feature allows seamless integration of Aisera audit data with existing Security Information and Event Management (SIEM) systems, enhancing security monitoring and compliance.
Integration Setup
Create the Splunk Integration:
Navigate to the Settings > Integrations page in the Aisera Admin UI
Click the + New Integration button
Search for and choose the Splunk icon
Name the integration
Provide the HTTP Event Collector (HEC) endpoint
Click Next
Set the authentication type and fill in the parameters
Data Source Setup
Add the Splunk Data Source:
Navigate to Settings > Data Source in the Aisera Admin UI
Choose + New Data Source
Search for and select the Splunk icon
Choose Event Trigger as the function
Choose Audit History and Audit History Data Type as the Data Types
Click Next
Event Triggers
Set the Event Triggers:
Navigate to AI Automation > Event Studio in the Aisera Admin UI.
Click the + New Event Trigger button.
Add a Name for the Trigger.
Select the new Event Forwarder option for the Event Handler Type
Choose Next
Set the Event Forwarder options
Select Splunk as the External System
Select your Splunk Data Source as the Data Sources option
Choose Audit History as the Data Type
Select AuditEvent as the Event Type
Click OK
Delivery Schedule
Set the Delivery Schedule:
Navigate to the Audit Trail page in the Aisera Admin U
Select your Splunk integration, choose event types, and set delivery schedules (real-time or batch).
Validation and Monitoring
Test the configuration to ensure connectivity
Monitor export status and error alerts in the Admin UI
Activation
Enable the export configuration to start streaming logs
Last updated
Was this helpful?