All Apps and Add-ons

DUO Log Add-on for Splunk setup

SamAlo
New Member

After installing the Duo Add-on i am not seeing "DUO Security 2fa logs" in data inputs. Is this compatible with version 6.4? Are there any special instructions after the app has been installed to get it to show up?

0 Karma
1 Solution

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

View solution in original post

0 Karma

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

0 Karma

SamAlo
New Member

Found it. Testing it out now.

Thanks for your help

0 Karma

robert_miller
Path Finder

Where did you find it? I am not seeing it and that URL doesn't work on 6.5.

0 Karma

SamAlo
New Member

Is it under Scripts? Under data inputs what "type" would it be under?

0 Karma

bawood
Path Finder

It should be it's own type, "DUO Security 2fa logs" in the Local section.

screenshot

0 Karma

bawood
Path Finder

You should also be able to find it under the "Add Data" dialog;
try appending this path to your Splunk server's url:
"en-US/manager/TA-DUOSecurity2FA/adddata/selectsource?input_mode=1"

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...