Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The Data Theorem Splunk application is a private Splunk App distributed by Data Theorem that automates log analysis. It searches for Web , Inc. for API Security. It it design to analyze Splunk logs for API attacks, API abuses, and API threats. It analyzes events as defined by the Splunk Common Information Model (CIM) add-on and sends the resulting access logs to Data Theorem for analysis. All customer data stays “On-Prem” or in your cloud, where only the metadata on events is shown on the Data Theorem portal. Splunk.pngImage RemovedThe data flow diagram is below:

splunk_arch.pngImage Added

System Requirements

...

The Data Theorem Splunk App searches analyzes only indexes containing Web CIM data, and uses only the below list of fields from the Web CIM model. The Web CIM fields contain metdata about requests, e similar to the information in an nginx or webserver access log. By using only defined fields on indexed Web CIM logs, there is minimal risk of accidental disclosure of sensitive data.

...

  • Download the Data Theorem Splunk App from the Data Theorem portal

  • Copy the Data Theorem API Key

splunk.pngImage Added

  • Install the app on Splunk deployment

  • When prompted, paste the API Key from the Data Theorem portal

...