Splunk Federated Search Integration with Cisco Security Analytics and Logging

Splunk Federated Search integration with Cisco Security Analytics and Logging is a cloud-based integration that

  • enables Splunk administrators to search Cisco Secure Firewall Threat Defense events stored in Cisco Security Analytics and Logging without direct ingestion into Splunk Cloud Platform

  • allows viewing analytics, running reports, and investigating incidents directly from the Splunk Cloud Platform interface, and

  • provides federated search capabilities across multiple Splunk deployments or environments from a single search interface.

Integration details

Terminology Note: In this document, "Cisco Security Analytics and Logging" refers specifically to Cisco Security Analytics and Logging (SaaS), which is a cloud-based platform that serves as a central repository for aggregated security event data.

Splunk Federated Search is a feature that is available in both Splunk Cloud Platform and Splunk Enterprise. You can use Splunk Federated Search to search and analyze data across multiple Splunk deployments or environments from a single search interface. For more information, see Splunk Federated Search.

Using the Splunk Federated Search feature, Cisco Security Analytics and Logging can be added as a dataset in the Splunk Cloud Platform. This integration enables Splunk administrators to search the Cisco Secure Firewall Threat Defense events stored in Cisco Security Analytics and Logging, without having to ingest them into the Splunk Cloud Platform directly. Splunk administrators can also view analytics, run reports, and investigate incidents directly from the Splunk Cloud Platform interface. For more information on the logs stored in Cisco Security Analytics and Logging, see Security Analytics and Logging (SaaS) in Security Cloud Control.

Benefits of Splunk Federated Search integration with Cisco Security Analytics and Logging:

  • Accelerated security investigations: Run federated queries on historical firewall logs without any storage overhead.

  • Wider data coverage: Enable the Splunk Cloud Platform users to leverage data stored in Cisco Security Analytics and Logging for security investigation, operational monitoring, and business intelligence.

  • End-to-end visibility: Correlate real-time alerts with historical data seamlessly.

  • Statistical analysis over time: Analyze large historical datasets for trends and threat patterns.

  • Compliance readiness: Maintain searchable, long-term logs to meet audit and regulatory needs.

  • Operational efficiency: Enable SecOps teams to access logs directly, eliminating the need for NetOps teams to provide access.