Define a Cisco Security Analytics and Logging dataset
Define a Cisco Security Analytics and Logging dataset in the Data Management app to facilitate federated search of Cisco Firewall data stored in a Cisco SAL tenant.
Create a Cisco Security Analytics and Logging (SAL) dataset to connect your Splunk Cloud Platform deployment to a Cisco SAL tenant and make its Cisco Firewall data available for federated searches.
The dataset creation workflow focuses on Cisco SAL tenant authentication. After you authenticate your Cisco SAL tenant, you can run federated searches from Splunk over the Cisco Firewall data stored in that tenant.
Each Cisco SAL tenant can authenticate a connection to only one Cisco SAL dataset. In other words, to search multiple Cisco SAL tenants, you must create a separate Cisco SAL dataset for each tenant.
If a Cisco SAL access token is already in use by a Cisco SAL dataset, no other Cisco SAL datasets can use that same Cisco SAL access token.
- Your user account on the SCP deployment must have a role with the
edit_connectionsandedit_datasetscapabilities. See Define roles on the Splunk platform with capabilities in Securing Splunk Cloud Platform. - You must obtain a Cisco Security Analytics and Logging access token from the Cisco administrator who oversees Cisco Security Analytics and Logging data.
- This token provides access to the Cisco SAL tenant that contains the Cisco Firewall data you want to run federated searches over.
- The Cisco SAL tenant to which the access token applies must reside in the same AWS region as your Splunk Cloud Platform deployment.
- You must create the Cisco SAL dataset within 7 days after Cisco Security Cloud Control generates the access token. Otherwise, get a new access token and start again.
-
For a detailed overview of Cisco SAL access token generation in Cisco Security Cloud Control, see Integration of Cisco Security Analytics and Logging with Splunk Federated Search in Security Cloud Control.
You now have a Cisco Security Analytics and Logging dataset that you can use for federated searches of Cisco Firewall Threat Defense security events.
After you create your Cisco Security Analytics and Logging dataset, do these things:
- Update the dataset description. See Manage a Cisco Security Analytics and Logging dataset.
- Ensure your users can access the new dataset with their federated searches. See Give your users role-based access control of federated datasets.
- Run federated searches over the dataset. See Write and run federated searches over federated datasets with SPL2.
-
Deactivate or activate federated search functionality for the dataset. See Manage a Cisco Security Analytics and Logging dataset.