Download the latest app tarball (neuvector_app.tar.gz
) from the neuvector/neuvector-splunk-app repository.
Download the latest app tarball from Splunkbase.
In the Splunk UI, click on the Apps dropdown, click "Find More Apps", then search for NeuVector Splunk App.
Install the app by either uploading the tarball or following the Splunkbase prompts.
- config syslog in NeuVector UI
goto Settings -> Configuration -> Syslog
a. set the server value as the IP address that the Splunk is runninng at
b. choose TCP as the protocol
c. set port number as 10514
d. choose Info Level
e. click SUBMIT to save the setting
- You can config multiple nodes to send syslog to your splunk instance and your splunk instance will receive these syslogs in real time.
Any user role.
- add east-west network violations
- add NeuVector dashboard