You can configure the Splunk adapter in Omnissa Access to automatically stream Omnissa Access audit events to Splunk in addition to the standard Omnissa Access analytics service.
Prerequisite: Configure an HTTP Event Collector (HEC) in Splunk
When configuring an HTTP Event Collector (HEC) in Splunk for use with Omnissa Access, note the following:
- Enable all tokens on the Global Settings page.
- Enable SSL.
- Set the index to send data to (for example,
main) and set the source type to_json. - After you create the collector, copy the generated token value.
Note: The Splunk UI may vary depending on your version. Refer to Splunk documentation for the latest HEC configuration steps.
Configure the Splunk integration in Omnissa Access
-
In the Omnissa Access Console, navigate to Integrations > SIEM.
-
Select the toggle to enable the Splunk adapter.
Note: Only one SIEM integration can be active at one time.
-
Configure the Splunk adapter.
Field Description Splunk Server URL The URL of the configured Splunk server. HEC Token The HTTP Event Collector token generated previously. Public SSL Certificate (Optional) If you are using a self-signed certificate, copy the public certificate here. Can be left blank if using a publicly trusted Root CA. Index (Optional) The specific index to which the logged events will be sent. This value defaults to the index designated in the HEC configured above. -
Select Configure.
Result
You can view and search the audit data in Splunk.
Was this page helpful?