TA-thehive-cortex icon indicating copy to clipboard operation
TA-thehive-cortex copied to clipboard

Check splunk connected with theHive

Open MohammadTtay opened this issue 1 year ago • 6 comments

Request Type

Help Wanted

Problem Description

theHive deployed on first server and i can access it like this : http://ip:9000 how can i connect my splunk on second server to theHive

If I want to explain in detail : I have created an account for theHive .Then i have taken an API in my theHive and set the API as password of my account in this TA as in doc said . can you help me in detail ? Screenshot 2024-05-26 143515

MohammadTtay avatar May 26 '24 11:05 MohammadTtay

Hi @MohammadTtay I don’t get your point sorry Isn’t adding a new instance what you want ?

LetMeR00t avatar May 26 '24 21:05 LetMeR00t

Yes i do . I just want to connect an instance But I dont know how? Actually i cannot be sure that my instance connected or not Can you explain for me in detail ?

MohammadTtay avatar May 26 '24 22:05 MohammadTtay

As soon as you have added it in the Instances lookup as shown, you can go in the dashboard used to get the alerts or the cases in the navigation bar. When selecting your instance in the dashboard using the corresponding input, you shall have the results shown in the dashboard. If not (nothing shown and a little warning/error appears in the panels of the dashboard), check the « Audit Logs » dashboard for any error or check the job logs in details to find any error.

LetMeR00t avatar May 27 '24 04:05 LetMeR00t

Hello @MohammadTtay Any update on this ? Thank you

LetMeR00t avatar Jun 29 '24 07:06 LetMeR00t

I should get certificate for my server which thehive running on it ?

MohammadTtay avatar Jul 06 '24 05:07 MohammadTtay

Hello I don’t get your point, did you have any log useful to determine what is the issue ? Thank you

LetMeR00t avatar Jul 06 '24 20:07 LetMeR00t

Hello I’m closing this old issue. Let me know if you need further help. Thank you

LetMeR00t avatar Sep 14 '24 06:09 LetMeR00t