Article

    Integrating with SIEM | Nightfall Documentation

    5 min read
    Last updated 1 month ago

    For Sumo Logic integration, configure an HTTP Logs and Metrics Source via the following instructions.

    This process will provide you with a URL endpoint (as seen in step 10). Copy this URL as you will use it to complete set up.

    For a Splunk integration, configure an HTTP Event Collector within Splunk via the following instructions.

    This process will provide you with a URL endpoint (as seen in this step). Copy this URL as you will use it to complete set up.

    Authentication via HTTP Header

    To authenticate to the HTTP Event Collector, you may add an Authorization http header as described in the Splunk documentation with your HTTP Event Collector token.

    Note that the Authorization HTTP header for HEC requires the "Splunk" keyword before the HEC token.

    Authentication via Query String

    It is also possible to add your HEC Token as part of the query string of the Collector URL. This can be done for both Splunk Cloud as well as Enterprise.

    If you are a Splunk Cloud customer, you will have to reach out to Splunk to enable the "allowQueryStringAuth" flag for your Splunk Cloud instance. This can be done by raising a Support Ticket with Splunk. This field can only be updated if on a Paid account. For a free/trial account, it will be unavailable.

    For Splunk Enterprise, you will have to enable query string authentication for your instance, by following these steps:

    Go to $SPLUNK_HOME/etc/apps/splunk_httpinput/local/inputs.conf file. Your tokens will appear by name in this file, in the form of http://<token_name>.

    Within the stanza for each token you want to enable query string authentication, add or change the following setting:

    Once the flag is enabled, please use the following steps to query the HEC Token within the URL String. For more information on Query string authentication from Splunk, please reference the docs here.

    You can specify the HEC token as a query string in the URL that you specify in your queries to HEC. This can be done with the format shown below:

    The following example shows a full Collector URL including a dummy HEC Token appended as a query string: (The example is for an Enterprise instance)

    Note: We will be using the /services/collector/raw endpoint instead of the /services/collector/event endpoint. This is because of the JSON format that webhooks from Nightfall will carry, which will only be accepted with the raw version of the HTTP Event Collector endpoint.

    For Splunk Cloud Customers:

    For Splunk Cloud customers, the above example URL will look different including the public facing HEC URL. The endpoint (/services/collector/raw?token=12345678-1234-1234-1234-1234567890AB) should remain the same, however. Since you are on a Splunk Cloud instance, this URL should already be visible to the Nightfall console, and you would be able to start using this Webhook URL in the Nightfall console. Please continue with the steps after this section to complete webhook set up.

    For Splunk Enterprise Customers:

    For Splunk Enterprise customers, there are a few extra steps to have the Splunk Collector exposed to the Nightfall webhook console below.

    The next step will be exposing the local host and port of the Splunk collector an HTTP Listening tool. This can be done by using an ngrok tunnel or nginx server, for example This is required so that the Enterprise Splunk instance is accessible to Nightfall's webhook from the console. Please make sure that port 8088 (this is the default port for receiving data for HEC) is accessible by navigating to "Global settings" in your Splunk Enterprise instance and enabling it.

    Steps for setting up a ngrok tunnel can be found here. If using a ngrok tunnel, the following command would generate a ngrok tunnel listening to the correct port and protocol for the collector:

    ./ngrok http https://localhost:8088

    Once complete, the ngrok tunnel should show you an HTTPS Forwarding address, that can be used as the ngrok host in the following step. (HTTPS is required by Nightfall's webhook URL validation)

    Your ngrok tunnel URL with your HEC auth token should now look something like this:

    https://<NGROK_HOST>/services/collector/raw?token=<YOUR_HEC_TOKEN>

    This will be your Webhook URL that you can use in the Nightfall console. Now you are all set to integrate alerts from your Nightfall webhook to your ngrok tunnel.