Installing Splunk Extension

To install the Splunk extension, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the menu icon to open the Global menu.

    The Global menu is displayed with menu items represented as tiles.

  2. In the Extensions tile, click Manage.

    The Extensions page is displayed, along with the installed and available extensions under their respective tabs.

    Figure 1: Available Extensions Tab

  3. Under the Available Extensions tab, in the Splunk tile, click Install.

    The Splunk installation side panel is displayed.

    Figure 2: Splunk Installation Side Panel

  4. Enter the required details as follows:

    • Name—Enter a name for the Splunk extension instance.

    • URL—Enter the specific URL for the HTTP Event Collector (HEC). Ensure that the URL is in the format:

      <protocol>://<host>:<port>/<client> where <client> is services, collector, or event.

    • Authentication Token—Enter the HEC token value.

    • Data Mapping—Select Clients as the Data Source. A data source indicates the location in HPE Aruba Networking Central from where data is to be exported to Splunk.

      • Enter an index name in the Map To Index field. This is a mandatory field. An index name must consist of only numbers, lowercase letters, underscores, and hyphens. An index name cannot begin with an underscore or hyphen or contain the word "kvstore".

      • Click the plus or delete icons to add or delete a Data Mapping configuration.

    Note:

    For more information, see the Set up and use HTTP Event Collector in Splunk Web topic in the Splunk Cloud Platform documentation portal.

  5. Click Install.