All Apps and Add-ons

DUO Log Add-on for Splunk setup

SamAlo
New Member

After installing the Duo Add-on i am not seeing "DUO Security 2fa logs" in data inputs. Is this compatible with version 6.4? Are there any special instructions after the app has been installed to get it to show up?

0 Karma
1 Solution

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

View solution in original post

0 Karma

bawood
Path Finder

I just tried installing on a clean 6.4.2 Splunk and the data input showed up and I'm not aware of any compatibility issues it would have with 6.4. It shouldn't even require a restart, but you could try that if you haven't already.

0 Karma

SamAlo
New Member

Found it. Testing it out now.

Thanks for your help

0 Karma

robert_miller
Path Finder

Where did you find it? I am not seeing it and that URL doesn't work on 6.5.

0 Karma

SamAlo
New Member

Is it under Scripts? Under data inputs what "type" would it be under?

0 Karma

bawood
Path Finder

It should be it's own type, "DUO Security 2fa logs" in the Local section.

screenshot

0 Karma

bawood
Path Finder

You should also be able to find it under the "Add Data" dialog;
try appending this path to your Splunk server's url:
"en-US/manager/TA-DUOSecurity2FA/adddata/selectsource?input_mode=1"

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...