About Federated Search for Cisco Security Analytics and Logging
Federated Search for Cisco Security Analytics and Logging (SAL) lets you run federated searches over Cisco Firewall events stored in your Cisco Security Analytics and Logging tenant.
Federated Search for Cisco Security Analytics and Logging (SAL) gives you visibility into Cisco Firewall events stored in your Cisco Security Analytics and Logging tenant without requiring you to ingest those events into your Splunk Cloud Platform deployment. After you set it up, you and your security operations teams can run remote searches for a variety of security use cases, including threat hunting, threat reporting, breach investigation, network troubleshooting, compliance auditing, dashboard monitoring, and data enrichment through correlation.
With Federated Search for Cisco Security Analytics and Logging, your security analysts can spend their time stopping threats instead of struggling to locate necessary data.
Cisco Security Analytics and Logging datasets
Federated Search is part of the Data Management app, where you set up your federated search experience by defining Cisco Security Analytics and Logging datasets. Each dataset represents a collection of Cisco Security Analytics and Logging firewall event logs stored in Amazon Web Services (AWS).
When you create your Cisco Security Analytics and Logging dataset, you start by obtaining an access token from your Cisco Security Analytics and Logging administrator. Then you use the token to authenticate a federated search connection between Splunk Cloud Platform and the Cisco SAL tenant and create a searchable dataset.
After you create your Cisco Security Analytics and Logging dataset, you can optionally deactivate federated search functionality for the dataset
What you need to get started
- You must have a Splunk Cloud Platform (SCP) deployment.
- Your user account on the SCP deployment must have a role with the
edit_connectionsandedit_datasetscapabilities. See Define roles on the Splunk platform with capabilities in the Manage Users and Security manual. - You must have a valid Cisco Security Analytics and Logging access token, generated by a Cisco Security Cloud Control account that has a Splunk Federated Search integration for Cisco Security Analytics and Logging.
- The Cisco SAL access token facilitates federated searches over the Cisco Firewall data contained within a specific Cisco SAL tenant.
- The Cisco SAL tenant to which the access token applies must reside in the same Amazon Web Services (AWS) region as your Splunk Cloud Platform deployment.
- For a detailed overview of Cisco SAL access token generation in Cisco Security Cloud Control, see Integration of Cisco Security Analytics and Logging with Splunk Federated Search in Security Cloud Control.
Checklist of tasks to set up Federated Search for Cisco SAL
Use this checklist to guide you through the cross-account setup of Federated Search for Cisco Security Analytics and Logging.
| Step | Task | Description | Service |
|---|---|---|---|
| 1 | Enable Splunk Federated Search Integration with Cisco Security Analytics and Logging | Coordinate with your Cisco Security Analytics and Logging administrator to ensure that their Cisco SAL instance is integrated with your Splunk platform federated search instance. | Cisco Security Analytics and Logging |
| 2 | Generate a Cisco Security Analytics and Logging access token | Coordinate with your Cisco Security Analytics and Logging administrator to generate the access token for the Cisco SAL tenant that contains the Cisco Firewall data you want to search. | Cisco Security Analytics and Logging |
| 3 | Define a Cisco Security Analytics and Logging dataset | Select Cisco Security Analytics and Logging as the data store, define the dataset, and authenticate your Cisco SAL tenant with the Cisco SAL access token. | Splunk Cloud Platform |
| 4 | Give your users role-based access control of federated datasets | Set up role-based access to Cisco Security Analytics and Logging datasets for your users, so that they can run federated searches over those datasets. | Splunk Cloud Platform |
| 5 | Monitor and troubleshoot the status of the Cisco SAL dataset connection | Work with the Cisco Security Analytics and Logging administrator to monitor and troubleshoot the connection between your Cisco SAL dataset and the Cisco SAL tenant that holds the firewall data your Cisco SAL dataset represents. | Cisco Security Analytics and Logging and Splunk Cloud Platform |
| 6 | Write and run federated searches over federated datasets with SPL2 | Run federated searches over your new Cisco Security Analytics and Logging dataset with SPL2. | Splunk Cloud Platform |