Define a Cisco Security Analytics and Logging dataset

Define a Cisco Security Analytics and Logging dataset in the Data Management app to facilitate federated search of Cisco Firewall data stored in a Cisco SAL tenant.

Create a Cisco Security Analytics and Logging (SAL) dataset to connect your Splunk Cloud Platform deployment to a Cisco SAL tenant and make its Cisco Firewall data available for federated searches.

The dataset creation workflow focuses on Cisco SAL tenant authentication. After you authenticate your Cisco SAL tenant, you can run federated searches from Splunk over the Cisco Firewall data stored in that tenant.

Each Cisco SAL tenant can authenticate a connection to only one Cisco SAL dataset. In other words, to search multiple Cisco SAL tenants, you must create a separate Cisco SAL dataset for each tenant.

If a Cisco SAL access token is already in use by a Cisco SAL dataset, no other Cisco SAL datasets can use that same Cisco SAL access token.

  • Your user account on the SCP deployment must have a role with the edit_connections and edit_datasets capabilities. See Define roles on the Splunk platform with capabilities in Securing Splunk Cloud Platform.
  • You must obtain a Cisco Security Analytics and Logging access token from the Cisco administrator who oversees Cisco Security Analytics and Logging data.
    • This token provides access to the Cisco SAL tenant that contains the Cisco Firewall data you want to run federated searches over.
    • The Cisco SAL tenant to which the access token applies must reside in the same AWS region as your Splunk Cloud Platform deployment.
    • You must create the Cisco SAL dataset within 7 days after Cisco Security Cloud Control generates the access token. Otherwise, get a new access token and start again.
    • For a detailed overview of Cisco SAL access token generation in Cisco Security Cloud Control, see ​Integration of Cisco Security Analytics and Logging with Splunk Federated Search in Security Cloud Control​.

  1. On your Splunk Cloud Platform deployment, in Splunk Web, select Data Management from the Apps panel.
  2. Navigate to the Datasets page, and then select Create dataset.
  3. Select the Cisco Security Analytics and Logging (SAL) data source, then select Next.
  4. On the Define dataset page, provide values for the fields and select Next.
    Setting Description
    Dataset name Supply a unique name for your dataset. The dataset name can contain only alphanumeric characters, underscores, and hyphens.
    Dataset description (Optional) Provide a description for your dataset.
  5. On the Authenticate token page, enter the Cisco SAL access token code into Cisco Security Analytics and Logging access token and select Validate token.
  6. If the access token passes validation and Splunk software returns the name and AWS region of the Cisco SAL tenant that you want to run federated searches over, select Next.
  7. On the Review page, review your dataset definition. If the details appear correct, select Create to create your dataset.

You now have a Cisco Security Analytics and Logging dataset that you can use for federated searches of Cisco Firewall Threat Defense security events.

After you create your Cisco Security Analytics and Logging dataset, do these things: