Skip to main content
NetApp Ransomware Resilience

Configure a Splunk SIEM in NetApp Ransomware Resilience

Contributors netapp-ahibbard

NetApp Ransomware Resilience provides native support for security information and event management (SIEM) with Splunk Cloud and Splunk Enterprise. By connecting Ransomware Resilience to a Splunk SIEM, you can automatically send event data for threat analysis and detection to streamline ransomware protection and event management.

Configure Splunk Cloud and Splunk Enterprise for threat detection

You must perform configurations in Splunk Cloud or Splunk Enterprise before authenticating the SIEM system in Ransomware Resilience.

Before you begin

Ransomware Resilience supports threat detection with Splunk Cloud and Splunk Enterprise. Before enabling the Splunk connection in Ransomware Resilience, you need to:

  • Enable an HTTP Event Collector in Splunk Cloud or Enterprise to receive event data via HTTP or HTTPS from the Console.

  • Create an Event Collector token in Splunk Cloud or Enterprise.

  • For Splunk Enterprise, if you choose Deliver via NetApp Console, allow inbound public internet traffic so Ransomware Resilience can push events to the HTTP Event Collector. If you choose Deliver via Console agent, the Console agent must be able to reach the HTTP Event Collector.

Enable an HTTP Event Collector in Splunk
  1. In Splunk Cloud or Enterprise, select Settings > Data Inputs.

  2. Select HTTP Event Collector > Global Settings.

  3. On the All Tokens toggle, select Enabled.

  4. To have the Event Collector listen and communicate over HTTPS rather than HTTP, select Enable SSL.

  5. Enter a port in HTTP Port Number for the HTTP Event Collector. Save the port number for the authentication process.

Create an Event Collector token in Splunk
  1. In Splunk Cloud or Enterprise, select Settings > Add Data.

  2. Select Monitor > HTTP Event Collector.

  3. Enter a Name for the token then select Next.

  4. Select a Default Index where events will be pushed, then select Review.

  5. Confirm that all settings for the endpoint are correct. Select the back button to make changes, otherwise select Submit.

  6. Copy the token and paste it in another document to have it ready for the Authentication step.

Authenticate Splunk with Ransomware Resilience

  1. In Ransomware Resilience, select Settings in the sidebar.

  2. In the Settings page, select Connect in the SIEM connection tile.

    Screenshot of SIEM connection options

  3. Choose Splunk as the SIEM provider.

  4. Review the Event collector and Token sections to confirm you have the correct information.

  5. Expand the Authentication section.

    1. Select the Protocol for the HTTP Event Collector. It's recommended that you use HTTPS, but if SSL isn't enabled for the HTTP Event Collector, select HTTP.

    2. Enter the Host and Port for the Splunk instance that runs the HTTP Event Collector. The port should match what you entered in the HTTP event collector process.

    3. Enter the event collector token you created in Splunk.

  6. Choose the event delivery route. To deliver SIEM events to your SIEM endpoint, select Deliver via NetApp Console. To route events through the Console agent already on your network, select Deliver via Console agent.

    If you chose Deliver via Console agent, select the Console agent to use from the dropdown menu.

  7. Select Connect to begin sending SIEM data.