Skip to main content

Log Management & Splunk Setup

Applies to:
SplunkDatadogAudit LogsSIEM Integration

Supported Integrations​

Splunk

Enterprise logging and analytics

Datadog

Cloud monitoring and security

Splunk Integration Setup​

1

Open Log Management Settings

Log in to DuoKey Cockpit and navigate to Administration Tab → Log Management Settings

2

Create new Syslog

Click Create new Syslog

3

Select Splunk Integration

In the Splunk integration card, click Install Now

4

Configure Connection

FieldDescription
NameName for the Log Management Provider
IP AddressIP Address of the Splunk API
Splunk PortPort number for Splunk connection
Splunk IndexTarget index for DKE logs
Splunk HEC TokenHTTP Event Collector authentication token
5

Test and Save

  1. Click Test Connection
  2. Click Save
Note

More information in the official Splunk - HTTP Event Collector guide.

Enable Splunk Logging​

1

Open Settings

In the Administration Tab, click Settings

2

Navigate to Audit Settings

Select the Tab Audit Record Retention

3

Enable Logging

Enable is AuditLog Database Enabled

4

Save Configuration

Click Save all

What Gets Logged​

Cryptographic Operations

  • Encrypt/Decrypt requests
  • Key usage events
  • Content key generation

User Activity

  • Login attempts
  • Configuration changes
  • Policy modifications

System Events

  • Service status changes
  • Key lifecycle events
  • Access policy evaluations