Announcing the SAVIYNT KNOWLEDGE EXCHANGE unifying the Saviynt forums, documentation, training, and more in a single search tool across platforms. Click HERE to read the Announcement.

Saviynt Audit Log Export to Splunk Version Less Than 9

Sivagami
Valued Contributor
Valued Contributor

I read from the document below that the Splunk Add-On is supported from Version 9. We are basically in V8. How do we export the audit logs to Splunk in this case? Any alternatives are much appreciated.

https://saviynt.freshdesk.com/support/solutions/articles/43000666823-splunk-integration-guide#Splunk... 

Sivagami_0-1673438511046.png

CC: @sagars 

-Siva

7 REPLIES 7

sagars
Saviynt Employee
Saviynt Employee

Hello @Sivagami ,

The Splunk add-on solution is build on top of splunk add-on builder which is available in below versions. If you are in any of the below mentioned version then please import the spl file provided in our documentation. 

 

Splunk-Addon.png

 Regards,

Sagar Srikantaiah

Sivagami
Valued Contributor
Valued Contributor

Thanks @sagars  for the response. Splunk team was able to import the add-on, but they are receiving 500 error on the page where they need to configure data ingestion.

Saviynt Version: v5.5 SP 3.12.7

Splunk Enterprise Version: v8.2.7

We imported the spl file in the below document and the add-on got installed on Splunk heavyweight forwarder and Splunk enterprise v8.2.7.

https://saviynt.freshdesk.com/support/solutions/articles/43000666823-splunk-integration-guide#Splunk...

https://splunkbase.splunk.com/app/6644

When we try to perform Step 5: Click on the SaviyntEvents Add-on and Create a New Input, below is the error received.

Sivagami_2-1673522775694.png

Below is the error when we click on the configuration tab as well.

Sivagami_3-1673522803541.png

Our Splunk team upgraded the heavy weight forwarder to V9 as well and still facing the same error mentioned above. Could you please assist?

-Siva

Sivagami
Valued Contributor
Valued Contributor

@sagars updated the documentation -https://saviynt.freshdesk.com/support/solutions/articles/43000666823-splunk-integration-guide#Splunk... with latest spl file and we installed the same in the new Splunk heavy weight forwarder (v9) that our Splunk team brought up & it worked.

Thanks Sagar for your help providing the new Saviynt add on!

Is it updated on new docs portal too ?


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

@rushikeshvartak ,

We are working on the new doc portal updates and will be ready by early next week.

Regards,
Sagar Srikantaiah

Sivagami
Valued Contributor
Valued Contributor

@sagars - Splunk Add-on Seems to not support pagination currently. Only first 50 records are being pulled in. Could you please check?

smithamg
Regular Contributor
Regular Contributor

We are also facing the same issue. Only 50 records are pulled at a time. Do we have any resolution for this?