Configuring the connector

This page describes how to configure the connector for log retrieval.

Configure a data input

  1. In Splunk Web, navigate to Apps  Sectigo Audit.

  2. Click Create new input.

    Add data source
  3. Complete the Add Sectigo Audit Config form.

    Configure data source

    The following table describes the configuration fields required to set up the SCM Audit data source.

    Field Description

    Name

    A user-defined name for the config.

    Interval

    The synchronization interval (minimum 5 seconds).

    Index

    The Splunk index to save logs to.

    API URL

    The URL of the SCM Audit API.

    The possible values are:

    Client ID

    The client ID of the SCM user.

    Client Secret

    The client secret of the SCM user.

  4. Click Add.

  5. Click Search.

    config created