jfrog / log-analytics-splunk

JFrog Splunk Log Analytics Integration
Apache License 2.0
9 stars 9 forks source link

Unable to find the Vulnerailities report in the Splunk. #52

Open SaiAvinash1205 opened 1 year ago

SaiAvinash1205 commented 1 year ago

Hi Team, we have used the same configuration for our X-ray integration, and we see all the logs except the Vulnerabilities. We would like to see the impacted artifacts URL, CVSS score of the artifacts on the splunk. Please let us know what needs to be done to get those logs too.

MahithaB commented 1 year ago

Hi @SaiAvinash1205

Did you specify the auth credentials in fluentd xray config? Also can you please check if Database sync is enabled in Xray. This can be done by going to your JPD, Administration > Xray > Settings > Database Sync

Can you please send an email to JFrog Support with your query and we'll help you out.

Thanks!

SaiAvinash1205 commented 1 year ago

Hi @MahithaB

We are able to see all the logs in the Splunk, except the SIEM vulnerabilities. How can we get the SIEM vulnerabilities from the Xray? Like CVSS Vulnerable artifacts, etc in the Splunk.

Except all the SIEM vulnerabilities we are able to get the other logs like Artifactory, Xray and Distribution logs in the Splunk.