icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading DUO Log Add-on for Splunk
SHA256 checksum (duo-log-add-on-for-splunk_122.tgz) 7661f7853ab584d6514d895404351feafb457891c57fba4085e783f128190266 SHA256 checksum (duo-log-add-on-for-splunk_121.tgz) a6813c97eae2c49aa88a5969f23f17ce18723dede7420254231d0e7332f3f6a5 SHA256 checksum (duo-log-add-on-for-splunk_120.tgz) 4bf1d96dfcee48e6db40899cf51da4f991e3fe210d11dd44697281cd702691fe SHA256 checksum (duo-log-add-on-for-splunk_110.tgz) d9de57973b6db554cfbc5ced2baac7d74907aebb75154e6c21bf34e21dc8d9b1 SHA256 checksum (duo-log-add-on-for-splunk_100.tgz) 3485ed4ab7dd410582bbd3384ec827b1eb323d85482ca1ff16fca960505636c4
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

DUO Log Add-on for Splunk

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Bring the power of Splunk searching and reporting to your DUO Security 2 factor logs. This TA indexes your authentication, telephony and administrator logs via DUO's API in JSON format, making it simple to generate usage metrics or monitor activity for security purposes.

Prerequisites:
DUO Security (https://duo.com/) admin account that has read access
to DUO Admin API.
You'll need the DUO API host, an Integration Key and Secret Key.

Deployment options:
For a single instance Splunk system, install by the usual installation method.

For distributed Splunk systems, the recommended place to install would be
on a heavy forwarder, but could also be setup on a search head as long as
the search head is configured to forward data to you indexing tier.

Configuration steps:
Once installed, a local input type titled "DUO Security 2fa logs" should be
listed under Data inputs.
-Select the "DUO Security 2fa logs" input.
-Click the "New" button at the top.
-Enter unique descriptive name for the input
-Enter relavant API host and credential information
-Set the number of days of historical data you'd like to pull the first time
After the first run of the input, this setting won't have any affect
as the checkpointing process maintains the time of the last indexed event.
-Set the interval in seconds at which datai is pulled, if it is set too low
Duo will return a 429 "too many requests" error so you may want to monitor
you're splunkd.log for this error message.
NOTE: From experience, you are likely to get the 429 response on a regular basis
if you use an interval of 300 seconds or less. YMMV.
-Select which DUO logs you want to enable
-Click "Next"
-If the API hostname and credentials verify correctly, the input setup
should complete successfully.

Optional configurations:
-Clicking "More settings" radio button, allows you to select a different
index than the default

Source repo is here: https://github.com/bawood/TA-DUOSecurity2FA
pull requests/suggestions are welcome.

Future roadmap:
-Splunk certification
-proxy support

Release Notes

Version 1.2.2
Feb. 13, 2019

removed old splunktalib which contained cruft that is blocking Splunk Cloud deployments

Version 1.2.1
Jan. 18, 2019

Updated Splunk Python SDK library and added Icons for app certification to enable install in Splunk Cloud.

Version 1.2.0
Dec. 13, 2016

-CIM compliance has been added

Version 1.1.0
Sept. 28, 2016

-Improve configuration validation and exception handling when calling DUO API.
-Added ability to pull DUO account summary info

Version 1.0.0
June 17, 2016

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.