Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Elastic Agent integration Airlock Digital #9887

Open
kalramani opened this issue May 16, 2024 · 2 comments
Open

Elastic Agent integration Airlock Digital #9887

kalramani opened this issue May 16, 2024 · 2 comments

Comments

@kalramani
Copy link
Contributor

We would like to see an Elastic Agent integration Airlock Digital# support case - #01360297.Internal enhancement request (ref. #18580

From our research, this will require Elastic Agent to Airlock Digital as this uses JSON over HTTPS, which can be collected by Splunk's HEC and elastics HTTP input (https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html).
You can then follow the 'HEC' setup process as documented here:

Reference links:
https://www.airlock.com/en/secure-access-hub/feature/reporting-and-siem-integration

Can someone please advise,

@JoshSchwarz
Copy link

JoshSchwarz commented May 17, 2024

@kalramani Can you clarify, do you mean Airlock Digital (https://www.airlockdigital.com/) or Airlock Secure Access Hub (https://www.airlock.com/)

If you are talking about Airlock Digital, you can send logs to Elastic in a range of formats as follows:

  1. Log into the Airlock interface;
  2. Click the Settings tab;
  3. In the Log Receiver drop-down, select one of the logging options and click Receiver Settings
  4. Complete the required information (IP, Port, etc.)
  5. Click Save
  6. Select 'Enable External Logging
  7. Click 'Configure Events and enable the event types you wish to log to Splunk
  8. Click Save

@kalramani
Copy link
Contributor Author

Airlock Secure Access Hub please.
Reference links:
https://www.airlock.com/en/secure-access-hub/feature/reporting-and-siem-integration

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants