Set-CASplunkEventSubscription
Use this command to modify a Splunk subscription.
Example: Disable a subscription
Example: Edit the subsystems included in a webhook subscription
Set-CASplunkEventSubscription -Connection $connection -SubscriptionId cd87b774-8e65-46e1-8520-da478c60c4c3 -Subsystems $newSubsystems
Remove-CASplunkEventSubscription
Use this command to remove a Splunk subscription.
Table 8. Available parameters
The ID of the subscription to remove. This parameter is required if the Subscription parameter is not specified. Use the Get-CASplunkEventSubscriptions command to find the ID.
Example: Remove a Splunk subscription Remove-CASplunkEventSubscription -Connection $connection -SubscriptionId $subscriptionId
Splunk event subscription wizard
From the Event Subscription Wizard you can add and edit a Splunk subscription.
1 Within Splunk, navigate to Settings | Data Inputs | HTTP Event Collector. Ensure that All Tokens are enabled under the Global Settings.
2 Click New Token and complete the steps in the wizard.To create a Splunk subscription
1 Click Add | Splunk subscription to open the wizard.
4 Click Next to select the events to forward based on subsystem and event date.
▪ By default, events start sending after the subscription is created. To change when to begin collecting and sending events, click Send events starting and select the desired date and time. You can select to send historical data; however, the time cannot be more than 30 days prior to the Change Auditor 7.0 installation date.
5 Click Finish.To edit the event URL for a Splunk subscription
2 Enter the new URL and click Finish.
Managing an IBM QRadar integration
IMPORTANT: To ensure that QRadar can read and present Change Auditor events, you need to import the extension created during the subscription creation or with the New-CAQRadarExtension command.
1 Open the QRadar console and select the Admin tab.
2 Select Extensions Management | Add.If prompted that the extension is not signed, select Install. When prompted to overwrite or keep existing data, select Overwrite.
1 Open the QRadar console and select the Admin tab.
2 Select Log Sources.
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center