Integrate ExtraHop with Splunk
The ExtraHop system monitors network and application performance by gathering data passively on the network. It offers deep and customizable analytics of wire data in real time.
Splunk collects and indexes data generated by applications, servers, and other devices. The Splunk big-data platform offers storage and correlation of a variety of data sources.
Integrating ExtraHop with Splunk enables long-term storage of wire data and correlation of wire data with other sources, such as machine data from logs.
Although there are many ways to export ExtraHop data to Splunk, we recommend that you install the ExtraHop Add-On for Splunk and the ExtraHop App for Splunk. The ExtraHop Add-On exports ExtraHop wire data metrics as Splunk events through the ExtraHop REST API, and the ExtraHop App adds important information to the exported data, such as device IP addresses.
Install and configure the ExtraHop Add-On for Splunk
The ExtraHop Add-On for Splunk enables you to export ExtraHop wire data metrics as Splunk events. You can export metrics about any activity group, device group, or application from an ExtraHop Discover or Command appliance. After the Splunk platform indexes the events, you can analyze the data through the dashboards in the ExtraHop App for Splunk or by creating your own visualizations.
Before you begin
The ExtraHop Add-On for Splunk requires the following specifications:- ExtraHop firmware version 7.1.2 or later
- Spunk Enterprise version 7.0 or later
Note: | Because this add-on runs on Splunk Enterprise, all Splunk Enterprise system requirements apply. |
Install and configure the ExtraHop App for Splunk
The ExtraHop App for Splunk adds information to the data that the ExtraHop Add-On for Splunk collects, including the IP addresses, MAC addresses, and hostnames of devices discovered by the ExtraHop system. The app also creates default inputs to collect metrics about HTTP, DNS, and storage activity and then builds dashboards to display that information.
Before you begin
The ExtraHop Add-On for Splunk requires the following specifications:- ExtraHop firmware version 7.1.2 or later
- Spunk Enterprise version 7.0 or later
- ExtraHop Add-On for Splunk 1.0.0 or later
Note: | Because this app runs on Splunk Enterprise, all Splunk Enterprise system requirements apply. |
Troubleshoot the ExtraHop App for Splunk
The ExtraHop Add-On for Splunk does not record the IP addresses, MAC addresses, and hostnames of devices by default for performance reasons. However, the ExtraHop App for Splunk includes a saved search that retrieves this information from an ExtraHop appliance and adds the information to Splunk.
- On the Splunk Web home screen, click .
- From the App drop-down menu, select ExtraHop App for Splunk.
- Click Run.
Thank you for your feedback. Can we contact you to ask follow up questions?