How Splunk Federated Search integration works with Cisco Security Analytics and Logging

This integration allows organizations to leverage both Splunk Cloud Platform capabilities and Cisco Security Analytics and Logging data through federated search functionality.

Summary

The key components involved in the Splunk Federated Search integration process are:

  • Firewall Threat Defense devices: Generate security events and send them to Cisco Security Analytics and Logging

  • Security Cloud Control: Manages the integration configuration and provides access tokens for Splunk

  • Splunk Cloud Platform: Configures dataset and role-based access controls

  • Splunk administrators: Configure the Splunk side of the integration and manage user access

Workflow

The completed integration enables users to perform federated searches of Cisco Security Analytics and Logging data directly from the Splunk Cloud Platform interface, providing unified access to security event data across both platforms.

Workflow of Splunk Federated Search Integration with Cisco Security Analytics and Logging

These stages describe how the Splunk Federated Search integration with Cisco Security Analytics and Logging works:

  1. Prerequisites phase: Firewall Threat Defense devices send security events to Cisco Security Analytics and Logging.
  2. Integration enablement phase: Security Cloud Control administrator enables the integration and shares access credentials.
  3. Splunk configuration phase: Splunk Cloud Platform administrator configures the federated search components.
    • Define a Cisco Security Analytics and Logging dataset. For more information, see Splunk Federated Search for Cisco Analytics and Logging (SAL) - Splunk Side.
    • Set up a Cisco Security Analytics and Logging dataset. For more information, see Splunk Federated Search for Cisco Analytics and Logging (SAL) - Splunk Side.
    • Give your users role-based access control of Cisco Security Analytics and Logging datasets. For more information, see Splunk Federated Search for Cisco Analytics and Logging (SAL) - Splunk Side.
  4. Verification and monitoring phase: Security Cloud Control administrator verifies integration status and monitors ongoing operations.
  5. Operational phase: Users search Cisco Security Analytics and Logging event logs through Splunk Cloud Platform.