Cisco Secure Access Alerts for Splunk, Overview

Splunk Integration with Secure Access Alerts

This guide describes how to set up the integration of Splunk with Cisco Secure Access Alerts. The integration of Splunk with a Secure Access Alert Rule sets up your instance of the Cisco Secure Access for Splunk app to receive alerts from Secure Access.

Before you add an Alert Rule for Secure Access, configure a Secure Access Webhook with the URL for the Splunk HTTP listener and select the Webhook when you configure the Alert Rule.

In an Alert Rule, configure an Alert Rule that publishes events when Secure Access detects changes to the resources in your organization.

Secure Access sends notifications formatted in JSON using the Secure Access Alert schema for Changes on Access Rules.

Set Up an Alert Rule in Secure Access for Splunk

  1. Add a Webhook in Secure Access. Configure the Webhook with the URL for the Splunk HTTP listener and the Basic authentication credentials for your Splunk account.
    • Add a Webhook in Secure Access as a Third-party integration. Configure the Webhook with the URL and Basic authentication credentials of the HTTP listener. For more information, see Third-Party Integrations API.
  2. Add an Alert Rule in Secure Access and select the Webhook that you configured for Splunk.
  3. Validate that your instance of the Splunk app receives the configured alerts from Secure Access.