Network Management

last person joined: 18 hours ago 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

Airwave 8.2.1.1 and Splunk

This thread has been viewed 2 times
  • 1.  Airwave 8.2.1.1 and Splunk

    Posted May 17, 2017 01:04 PM

    We have a requirement to start sending logs from Airwave to Splunk.  I see previous discussions in this forum using ClearPass to Splunk. Can we send logs directly from Airwave to Splunk?  Any configuration is appreciated.



  • 2.  RE: Airwave 8.2.1.1 and Splunk

    EMPLOYEE
    Posted May 17, 2017 01:13 PM

    Hi

     

    We could forward logs from Airwave to external syslog server. Navigate to AMP Setup > General> Exteranl logging section to configure.

     

    Regards,

    Pavan



  • 3.  RE: Airwave 8.2.1.1 and Splunk

    Posted May 17, 2017 02:10 PM

    Thanks for the reply, I will test during the next maintenance window.  

     



  • 4.  RE: Airwave 8.2.1.1 and Splunk

    Posted Aug 08, 2017 03:07 AM

    Hello,

     

    What type of data are you trying to correlate? You can configure Airwave to send to an external syslog from the AMP Setup -> General page.

     

    You can integrate Splunk into AirWave using the API so you can lookup a MAC address inside of Splunk and have it show you data from ClearPass, controller syslogs and AirWave.

     

    Hope this helps, Thanks.



  • 5.  RE: Airwave 8.2.1.1 and Splunk

    Posted Aug 14, 2017 12:58 AM

    SandraLynn

     

    I don't suppose you have details on setting up this API integration?

     

    Any suggested starting points?

     

    Glen.