LetMeR00t / TA-thehive-cortex

Technical add-on for Splunk related to TheHive/Cortex from TheHive project
GNU Lesser General Public License v3.0
47 stars 11 forks source link

Check splunk connected with theHive #91

Open MohammadTtay opened 1 month ago

MohammadTtay commented 1 month ago

Request Type

Help Wanted

Problem Description

theHive deployed on first server and i can access it like this : http://ip:9000 how can i connect my splunk on second server to theHive

If I want to explain in detail : I have created an account for theHive .Then i have taken an API in my theHive and set the API as password of my account in this TA as in doc said . can you help me in detail ? Screenshot 2024-05-26 143515

LetMeR00t commented 1 month ago

Hi @MohammadTtay I don’t get your point sorry Isn’t adding a new instance what you want ?

MohammadTtay commented 1 month ago

Yes i do . I just want to connect an instance But I dont know how? Actually i cannot be sure that my instance connected or not Can you explain for me in detail ?

LetMeR00t commented 1 month ago

As soon as you have added it in the Instances lookup as shown, you can go in the dashboard used to get the alerts or the cases in the navigation bar. When selecting your instance in the dashboard using the corresponding input, you shall have the results shown in the dashboard. If not (nothing shown and a little warning/error appears in the panels of the dashboard), check the « Audit Logs » dashboard for any error or check the job logs in details to find any error.

LetMeR00t commented 2 weeks ago

Hello @MohammadTtay Any update on this ? Thank you

MohammadTtay commented 1 week ago

I should get certificate for my server which thehive running on it ?

LetMeR00t commented 1 week ago

Hello I don’t get your point, did you have any log useful to determine what is the issue ? Thank you