Send records from ExtraHop to Splunk
You can configure the ExtraHop system to send transaction-level records to a Splunk server for long-term storage, and then query those records from the ExtraHop Web UI and the ExtraHop REST API.
Before you begin
- You must have version 7.0.3 or later of Splunk Enterprise and a user account that has administrator privileges.
- You must configure the Splunk HTTP Event Collector before your Splunk server can receive ExtraHop records. See the Splunk HTTP Event Collector documentation for instructions.
Note: | Any triggers configured to send records through commitRecord to an Explore appliance are automatically redirected to the Splunk server. No further configuration is required. |
Send records from ExtraHop to Splunk
Complete this procedure on all connected ExtraHop
systems.
Important: | If your ExtraHop system includes a Command appliance, configure all appliances with the same recordstore settings or transfer management to manage settings from the Command appliance. |
After your configuration is complete, you can query for
stored records in the ExtraHop Web UI by clicking Records from
the top menu.
Transfer recordstore settings
If you have a Command appliance connected to your Discover appliances, you can configure and manage the recordstore settings on the Discover appliance, or transfer the management of the settings to the Command appliance. Transferring and managing the recordstore settings on the Command appliance enables you to keep the recordstore settings up to date across multiple Discover appliances.
Recordstore settings are configured for connected
recordstores and do not apply to the Explore appliance.
Thank you for your feedback. Can we contact you to ask follow up questions?