For log observer connect for Cisco AppDynamics, you must configure a Splunk Cloud Service account user. This service account user must have access to the indexes in Splunk Cloud Platform, where tiers may be sending logs

To configure the Splunk Cloud Service account user, you must be assigned to the Splunk admin role.

Setup Service Account User in Splunk Cloud Platform

Configure a role and a user in Splunk Cloud Platform as follows. You can create a new role and user or use an existing role and a user.

Create or Select a Role 

  1. Go to Settings > Roles.
  2. Create or select the role you want for the Splunk AppDynamics service account. 
    1. To create a new role, click New Role.
    2. To select an existing role, click Edit > Edit next to the role you want to use.
  3. On the Capabilities tab, ensure that edit_tokens_own and search are selected. 

    Ensure that indexes_list_all is not selected.

     
  4. On the Indexes tab in the Included column, deselect *(All internal indexes) and select the indexes where AppDynamics application logs are stored.
  5. On the Resources tab:
    1. For Role search job limit, enter 0 for both the Standard search limit and Real-time search limit.
    2. For User search job limit, enter 0 for both the Standard search limit and Real-time search limit.
    3. For Role search time window limit, select Custom time for the "maximum time window for searches for this role" and enter 2592000 (2592000 seconds equates to 30 days).
    4. For Role search time window limit, select Custom time for the "earliest searchable event time for this role" and enter 7776000 (7776000 seconds equates to 90 days).
  6. Click Save if you are configuring an existing user or Create for a new user.

Assign the Role to a New or Existing User

  1. In Splunk Cloud Platform, go to Settings > Users.
  2. Create the user for the AppDynamics service account by clicking New User or Edit > Edit next to the existing user for whom you want to have the new role.
  3. For new users, enter a name and set a password. Safely retain and send the username and password to your AppDynamics Administrator, who will need these credentials to integrate Cisco AppDynamics with the Splunk Cloud Platform.
  4. In the Assign roles section, assign the user the role you created or updated in Create or Select a Role.
  5. Click Create or Save.