Configuring the Splunk Add-On for AWS

Jamf Protect Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Requirements

Super Admin access to your organization in Jamf Security Cloud to retrieve the credentials for the AWS S3 bucket.

Note:

These configuration settings are provided for information only and are not guaranteed to work with all versions of Splunk. If you require assistance, contact Jamf Support.

  1. In Splunk, navigate to Apps > Find More Apps.
  2. Search for and install the Splunk Add-on for Amazon Web Services.

    Splunk Add-On for AWS is added to the list of available apps.

  3. In Jamf Security Cloud, navigate to Integrations > Data Streams.
  4. Select Threat Events Stream.
  5. Select the AWS S3 tab in the Streaming Target area.
  6. Retrieve the credentials for the AWS S3 bucket.
    Note: If you cannot see the credentials, then you are not a Super Admin of your organization in Jamf Security Cloud, and you will not be able to proceed.
  7. If secure logs are not already being exported to the S3 bucket, click Export to begin the process.
  8. In Splunk, select Splunk Add-On for AWS > Configurations.

    If this is the first time you have configured this app, you will be prompted to create an account.

  9. Click Add on the Account tab.
  10. Complete the fields with the following values:
    • NameJamf
    • UsernameThe AWS access key
    • PasswordThe AWS secret key
    • Region CategoryGlobal
  11. Click Add.
The account is configured and Splunk can access the AWS S3 bucket.