Security

how to pull authentication logs from duosecurity

avshch
New Member

Hello,
How to pull authentication logs from duosecurity (www.duo.com) 2FA cloud service provider.
Any help is appreciated.
Thanks,

0 Karma

MuS
Legend

Hi avshch,

I have no idea about duo security, but I can google that for you http://bfy.tw/4ro7 and found this https://duo.com/docs/adminapi#logs

Which means you can get your logs using the API from duo.com ; that said you should be able to use the REST Modular input https://splunkbase.splunk.com/app/1546/ to pull the logs and index them in Splunk.

Hope that helps ...

cheers, MuS

bmacias84
Champion

Yes this is true, but you will need a custom handler and will need to track the ** mintime** request param to prevent duplicate events.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...