Log Management & Splunk Setup
Log Management & Splunk Setup
Configure logging integrations for DKE audit trails
Applies to:
SplunkDatadogAudit LogsSIEM Integration
Supported Integrations
Splunk
Enterprise logging and analytics
Datadog
Cloud monitoring and security
Splunk Integration Setup
1
Open Log Management Settings
Log in to DuoKey Cockpit and navigate to Administration Tab → Log Management Settings
2
Create new Syslog
Click Create new Syslog
3
Select Splunk Integration
In the Splunk integration card, click Install Now
4
Configure Connection
| Field | Description |
|---|---|
| Name | Name for the Log Management Provider |
| IP Address | IP Address of the Splunk API |
| Splunk Port | Port number for Splunk connection |
| Splunk Index | Target index for DKE logs |
| Splunk HEC Token | HTTP Event Collector authentication token |
5
Test and Save
- Click Test Connection
- Click Save
Note
More information in the official Splunk - HTTP Event Collector guide.
Enable Splunk Logging
1
Open Settings
In the Administration Tab, click Settings
2
Navigate to Audit Settings
Select the Tab Audit Record Retention
3
Enable Logging
Enable is AuditLog Database Enabled
4
Save Configuration
Click Save all
What Gets Logged
Cryptographic Operations
- Encrypt/Decrypt requests
- Key usage events
- Content key generation
User Activity
- Login attempts
- Configuration changes
- Policy modifications
System Events
- Service status changes
- Key lifecycle events
- Access policy evaluations