Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Splunk

Want to summarize with AI?

Log in

Learn how the Splunk integration sends Cisco Multicloud Defense alerts to Splunk through a configured Alert Service Profile and associated Alert Rule.


Once configured, Multicloud Defense alerts will sent to an API gateway using the defined Alert Service Profile and Alert Rule.


Create a Splunk Profile Service

Use the following procedure to create an alert profile for the Splunk service:

Before you begin

You must have the following configured and ready:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Services.

2.

Click Create.

3.

Name - Enter unique name for the alert integration.

4.

Description (optional) - Enter a description for the alert integration.

5.

Type - Using the pulldown, choose Splunk.

6.

API Key - Copy the Splunk API key generated above, or other PagerDuty API Key as desired.

7.

Check the Skip Verify Certificate box if your server doesnt have certificates with SAN field matching with domain. If you server does have ceritficats with SAN fields matching the domain, leave this unchecked.

8.

Index(default - main) is Splunk's default index where all the processed data is stored. This is provided when you configure the Splunk HEC.

9.

Enter the API URL for the Splunk HTTP Event Collector. We recommend this URL https://<host>:<port>/services/collector .

10.

Click Save.

What to do next

Create an alert rule with this new profile.


Create a Splunk Rule

Use the following procedure to create a rule containing the splunk alert service:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Alert Rules.

2.

Click Create.

3.

Profile Name - Enter unique name for the integration. Example mcd-mssentinel-alert-rule.

4.

(Optional)Description - Enter a description for the aler trule.

5.

Alert Profile - Expand the drop-down menu and select a Microsoft Teams alert profile.

6.

Type - Expand the drop-down menu and select one of the following types:

  • System Logs

  • Audit Logs

  • Discovery

If you select Audit Logs, there are no other configurable items. Click Save to finalize the rule.

7.

If you select either System Logs or Discovery as your Type, then expand the Sub Type drp-down menu and select one of the following options:

  • Gateway

  • Account

  • Controller

8.

Expand the Severitydrop-down menu and select one of the following labels. Note that the options below are dependent on the Type you selected in step 7.

  • Info

  • Warning

  • Medium

  • High

  • Critical

9.

Enabled - This option is checked by default to enable and implement this alert immediately after saving. Unceck this box if you do not to immediately apply the rule to your environment.

10.

Click Save.