Requirements for Splunk Federated Search Integration with Cisco Security Analytics and Logging

Prerequisites

Ensure you meet these requirements before initiating the Splunk Federated Search integration with Cisco Security Analytics and Logging.

  • You must have Super Admin user role in Security Cloud Control platform to initiate the Splunk Federated Search integration with Cisco Security Analytics and Logging by generating the access token. Users without Super Admin privileges can only view the Splunk Federated Search integration flow.

  • Ensure that the Firewall Threat Defense devices deployed on the Security Cloud Control platform are sending intrusion, file and malware, and connection events to Cisco Security Analytics and Logging.

Limitation

By default, only up to 30 days of log data from Cisco Security Analytics and Logging is available for federated search.