Community
Questions Library
Docs
Blog
Events
Swag
Github
Slack
JupiterOne
Discussions
Release Notes
Contact Us
Splunk - AskJ1 Community
<main> <article class="userContent"> <h2 data-id="splunk-jupiterone-integration-benefits">Splunk + JupiterOne Integration Benefits</h2> <ul><li>Import JupiterOne alert data to your Splunk account.</li> <li>View alerts on a Splunk dashboard.</li> <li>Link back to alerts in JupiterOne for easy access to additional information.</li> <li>Use J1QL queries in your Splunk searches</li> <li>Trigger a search in JupiterOne for any data field in Splunk from your Splunk instance.</li> </ul><h2 data-id="how-it-works">How it Works</h2> <ul><li>Splunk periodically imports alert details from JupiterOne.</li> <li>Write your own Splunk searches to find data about JupiterOne alerts.</li> <li>View JupiterOne alerts on a dashboard in Splunk with breakdowns by severity, over time, active and dismissed.</li> </ul><h2 data-id="requirements">Requirements</h2> <ul><li>A JupiterOne API key and your JupiterOne account ID.</li> <li>Splunk Enterprise 8.0, 8.1, 8.2 or Splunk Cloud</li> <li>Permission to install new add-ons and apps in Splunk.</li> </ul><h2 data-id="support">Support</h2> <p>If you need help with this integration, contact <a rel="nofollow" href="https://community.askj1.com">JupiterOne Support</a>.</p> <h2 data-id="integration-instructions">Integration Instructions</h2> <h3 data-id="in-jupiterone">In JupiterOne</h3> <ol><li><a rel="nofollow" href="https://support.jupiterone.io/hc/en-us/articles/360025847594-Enable-API-Key-Access">Generate an API key</a>.</li> <li>Look up your <code class="code codeInline" spellcheck="false" tabindex="0">accountId</code> by executing this query in your JupiterOne account: <code class="code codeInline" spellcheck="false" tabindex="0">find jupiterone_account</code>. The result has a column labeled <code class="code codeInline" spellcheck="false" tabindex="0">accountId</code>.</li> </ol><h3 data-id="install-add-on-and-app-in-splunk">Install Add-on and App in Splunk</h3> <ol><li>On the Splunk home dashboard, use the <strong>Find More Apps</strong> link to find and install the JupiterOne add-on and JupiterOne app.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/O31SBPX7GKXG/splunk-find-more-apps.png" alt="splunk-find-more-apps" class="embedImage-img importedEmbed-img"></img></p> <p>or</p> <ol><li>Download the <a rel="nofollow" href="https://splunkbase.splunk.com/app/6138">add-on</a> or <a rel="nofollow" href="https://splunkbase.splunk.com/app/6139">App</a> package from the Splunkbase marketplace.</li> <li>In Splunk, navigate to <strong>Apps > Manage Apps</strong> by clickingthe gear icon in the upper-left corner.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/Y5B4CFKHR3KL/splunk-apps-manage-apps.png" alt="splunk-apps-manage-apps" class="embedImage-img importedEmbed-img"></img></p> <ol start="3"><li>In the top-right corner, select <strong>Install app from file</strong>.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/SSRUM9OBCEBO/splunk-install-app-from-file.png" alt="splunk-install-app-from-file" class="embedImage-img importedEmbed-img"></img></p> <ol start="4"><li>Select <strong>Choose File</strong> and select the add-on or app package you downloaded.</li> <li>Select <strong>Upload</strong> and follow the instructions.</li> </ol><h3 data-id="configure-the-add-on-in-splunk">Configure the Add-on in Splunk</h3> <ol><li>In Splunk, navigate to <strong>JupiterOne Add-on for Splunk</strong>.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/ZAZ95K3NFPEH/splunk-menu-add-on.png" alt="splunk-menu-add-on" class="embedImage-img importedEmbed-img"></img></p> <ol><li>Click <strong>Configuration</strong>.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/ATZ13U6IDURH/splunk-j1-account-config.png" alt="splunk-j1-account-config" class="embedImage-img importedEmbed-img"></img></p> <ol start="2"><li>Click <strong>Add</strong> to create a new JupiterOne account configuration.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/I0EA0FEFDRLW/splunk-configure-j1-account.png" alt="splunk-configure-j1-account" class="embedImage-img importedEmbed-img"></img></p> <ol start="3"><li>In the Add JupiterOne Account screen, enter an <strong>Account Name</strong>, the <strong>Account Id</strong>, and the <strong>API Key</strong>. Click <strong>Add</strong> when finished.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/DXVBHHONN7TY/splunk-add-j1-account.png" alt="splunk-add-j1-account" class="embedImage-img importedEmbed-img"></img></p> <ol start="4"><li>If needed, configure a proxy on the Proxy tab.</li> <li>If required, change the log level on the Logging tab. The default is INFO.</li> <li>Navigate to the <strong>Inputs</strong> tab.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/0RYMCA6ERXKA/splunk-j1-inputs.png" alt="splunk-j1-inputs" class="embedImage-img importedEmbed-img"></img></p> <ol start="7"><li>Click <strong>Create New Input</strong>.</li> <li>Enter the details and click <strong>Add</strong>.</li> </ol><p><img src="https://us.v-cdn.net/6035534/uploads/FWRDBMR9G7F5/splunk-j1-inputs-fields.png" alt="splunk-j1-inputs-fields" class="embedImage-img importedEmbed-img"></img></p> <table><thead><tr><th>Field Name</th> <th>Field Description</th> </tr></thead><tbody><tr><td>Name*</td> <td>Unique name for the data input.</td> </tr><tr><td>Interval*</td> <td>Time interval of input in seconds. How often JupiterOne collects the data.</td> </tr><tr><td>Index*</td> <td>Index where data is stored.</td> </tr><tr><td>JupiterOne Account*</td> <td>Account that was configured in the <strong>Configuration</strong> tab.</td> </tr><tr><td>Pull Alert Related Objects</td> <td>If enabled, pulls data for entities in Alert.</td> </tr><tr><td>Start DateTime</td> <td>Date in UTC when you want to start collecting data. Default is 30 days in the past.</td> </tr></tbody></table><p><code class="code codeInline" spellcheck="false" tabindex="0">*</code> denotes required field</p> <h3 data-id="configure-the-app-in-splunk">Configure the App in Splunk</h3> <p>AFter you have configured the add-on and it is running, the app starts working. There is no configuration needed.</p> <p>More details are available on the Splunkbase marketplace for the <a rel="nofollow" href="https://splunkbase.splunk.com/app/6138">add-on</a> and the <a rel="nofollow" href="https://splunkbase.splunk.com/app/6139">App</a>.</p> </article> </main>