Splunk Integration
  • 26 Nov 2023
  • Dark
    Light

Splunk Integration

  • Dark
    Light

Article Summary

The Bot Defender App for Splunk allows you to add prebuilt dashboards to help you visualize your Bot Defender logs. These dashboards allow you to see key data points and identify potential spikes in activity across all logs from within Splunk.

Configuring the Integration

  1. Configure a Splunk integration as specified here
  2. From within your Splunk instance's App menu, click on the Find More Apps link.
  3. On the resulting Browse More Apps page, search for PerimeterX.
  4. Locate the PerimeterX Bot Defender App for Splunk in the results.
  5. Click the Install button.
  6. Login to your Splunk.com account to download and install the App.
Optional Additional Steps
The PerimeterX Bot Defender App for Splunk supports obtaining data from a specific index and events of a specific source type. As an optional step, you can choose to configure your Splunk instance to index the data under a custom index and with a specific source type.

Validating App Installation

  1. Login to your Splunk instance
  2. Click on the App menu and confirm that the PerimeterX Bot Defender App for Splunk is listed872
  3. Click on the PerimeterX Bot Defender App for Splunk menu item to load the App.2838

Using the Application

No Data is Displayed in the App
Until your Splunk begins receiving the data, the App will not show any widgets. The App will also not show any data until you have select the proper index that contains your PerimeterX Bot Defender logs.

Once PerimeterX support has confirmed that the integration is complete, you should begin receiving data into your Splunk instance. Once data begins populating into your Splunk, you can begin using the PerimeterX Bot Defender App for Splunk.

When you access the PerimeterX Bot Defender App for Splunk, you will be presented with the dashboard for your data. The panels will be blank until you have at least selected index from the Index drop down. Once that is selected, the data panels will populate with data. You can additionally choose to select the sourc etype specified for your Bot Defender data if you added a custom sourcetype for these logs.

In addition, the Data Filter drop downs allow you to filter the graphs by selected fields. Below is an example of the App with no filtering and the panels populated

1343



Was this article helpful?