Enable Splunk Federated Search Integration with Cisco Security Analytics and Logging

Generate a secure access token that authenticates and authorizes interactions between the Splunk Cloud Platform and the Cisco Security Analytics and Logging service for data access.

Use this procedure to generate the access token that can be copied and shared with the Splunk administrator to enable access to Cisco Security Analytics and Logging data. The secure access token is automatically generated and is used to authenticate and authorize interactions between the Splunk Cloud Platform and the Cisco Security Analytics and Logging service. These tokens are generated per tenant and can be renewed manually.

Procedure


Step 1

From the left pane, choose Administration > Integrations > Splunk > Splunk Federated Search.

Step 2

Under the Splunk Federated Search tab, review the preintegration details and click Begin integration.

Image of Splunk Federated Search tab

The initial log availability is up to 30 days, that is, up to 30 days of firewall event data is available for Splunk Federated Search.

Note

This step may take a few minutes to complete. The time taken depends on the volume of event data stored in Cisco Security Analytics and Logging.

You can click Cancel integration to cancel the integration at this stage. No changes will be made to your Cisco Security Analytics and Logging environment and access will not be granted to Splunk Cloud Platform if you cancel the integration.

Step 3

After you see the Configuration successful message, click Generate token.

If you see the Configuration failed message, click Retry setup.

Step 4

From the Splunk Federated Search access token section, copy the access token and share it with the Splunk administrator.

Splunk Federated Search access token screen

This access token is valid for 7 days (168 hours) from the time it is generated. The Splunk administrator must create the dataset before the access token expires.

Note

If you leave this page without copying the displayed access token, the access token is lost and you must regenerate a new access token by clicking Regenerate token.


You have successfully generated an access token that enables Splunk administrator access to Cisco Security Analytics and Logging data through the Splunk Cloud Platform integration.

What to do next

Follow the steps in Splunk Federated Search for Cisco Analytics and Logging (SAL) - Splunk Side to:

  1. Define a Cisco Security Analytics and Logging dataset.

  2. Set up a Cisco Security Analytics and Logging dataset.

  3. Give your users role-based access control of Cisco Security Analytics and Logging datasets.