You are here

How to Deploy Airlock App for Splunk

Affects product: 
Airlock WAF
Affects version(s): 
7.x

The Airlock App for Splunk is split into two parts:

  1. The free Splunk Add-Ons which allow a fast and easy integration by parsing the logs correctly and provide the Airlock WAF field names as well as the corresponding Splunk CIM alias.
  2. The commercial Splunk App itself depends on those Splunk Add-Ons and contains dashboards for different use cases to simplify analytic tasks. For a brief overview about the app please consider our factsheet.

While the Splunk Add-Ons are free, the Splunk App with its dashboards must be purchased from Ergon Informatik AG. Please send an email to order@airlock.com to get an offer and license. The integration of Airlock WAF into Splunk is described in the document below.

Note: The procedure for calculating the log volume described in section 5.1.1 is not applicable for Airlock Gateway 8.x. However, the number of log messages can be easily calculated using Kibana.

 

AttachmentSize
PDF icon Deploy_Airlock_App_for_Splunk620.63 KB
Knowledge Base Categories: