DUO Data
The Duo Security Add-on is required to collect the data.
Splunkbase Download: https://splunkbase.splunk.com/app/3504
Installation Guide: https://duo.com/docs/splunkapp
How to Install and Configure the Duo Security Add-on:
-
Install the Add-on on the Heavy Forwarder.
- Configure the Add-on on the Heavy Forwarder.
- Create an index named duo or update the macro definition in Cyences’ configuration page with your index.
- Install the Add-on on the Search Head.