Splunk Integration

Splunk Integration

ThreatLocker offers the ability to send Application Control (Whitelisting), and Storage Control policy audit information to your Splunk Enterprise or Splunk cloud server. In order to use Splunk you must first request that Splunk integration is enabled on your account.

ThreatLocker Standard Edition includes 10 Splunk writes per device per day.

ThreatLocker Enterprise Edition includes 200 Splunk writes per device per day.

How to log when an application is opened with Splunk.

You may have a requirement to log when an application is opened with your Splunk server. This information could be useful to tracking access to sensitive applications. To report information when an application is opened to your Splunk instance.

  1. Select Application Control > Policies from the navigation menu;
  2. Select the edit icon next to an existing application, or create a new application;
  3. Scroll down to the bottom of the page under the section “So you want to report this information to your Splunk Instance?” section, and select Yes;
  4. Enter the Splunk HTTP receiver URL and the token value (See Creating a Splunk Event Collector);
  5. Save your policy.

Creating a Splunk Event Collector

  1. From your Splunk Instance, select settings > add data;
  2. Click HTTP Event Collector.
  3. In the Name field, enter a name for the token.
  4. (Optional) In the Source name override field, enter a name for a source to be assigned to events that this endpoint generates.
  5. (Optional) In the Description field, enter a description for the input.
  6. (Optional) If you want to enable indexer acknowledgment for this token, click the Enable indexer acknowledgment checkbox.
  7. Click Next.
  8. (Optional) Make edits to source type and confirm the index where you want HEC events to be stored. See Modify input settings.
  9. Click Review.
  10. Make edits to source type and confirm the index where you want HEC events to be stored. See Modify input settings.
  11. Click Review.

Leave a comment!

All fields marked with an asterisk* are required.