Download page Configure Splunk Service Account User.
Configure Splunk Service Account User
For log observer connect for Cisco AppDynamics, you must configure a service account user in your Splunk Cloud Platformor Splunk Enterprise, depending on your deployment. This service account user must have access to the indexes in Splunk Platform, where tiers may be sending logs.
To configure the Splunk service account user, you must be assigned to the Splunk admin role.
Setup Service Account User in Splunk Platform
Configure a role and a user in Splunk Cloud Platform or Splunk Enterprise as follows. You can create a new role and user or use an existing role and a user.
Create or Select a Role
In your Splunk deployment, go toSettings > Roles.
Create or select the role you want for the Splunk AppDynamics service account.
To create a new role, click New Role.
To select an existing role, click Edit > Edit next to the role you want to use.
On theCapabilitiestab, ensure thatedit_tokens_ownandsearchare selected.
Ensure thatindexes_list_allis not selected.
On theIndexestab in theIncludedcolumn, deselect*(All internal indexes)and select the indexes where AppDynamics application logs are stored.
On theResourcestab:
For Role search job limit, enter 0 for both the Standard search limit and Real-time search limit.
For User search job limit, enter 0 for both the Standard search limit and Real-time search limit.
For Role search time window limit, select Custom time for the "maximum time window for searches for this role" and enter 2592000 (2592000 seconds equates to 30 days).
For Role search time window limit, select Custom time for the "earliest searchable event time for this role" and enter 7776000 (7776000 seconds equates to 90 days).
Click Save if you are configuring an existing user or Create for a new user.
Assign the Role to a New or Existing User
In Splunk deployment, go toSettings > Users.
Create the user for the AppDynamics service account by clicking New User or Edit > Edit next to the existing user for whom you want to have the new role.
For new users, enter a name and set a password. Safely retain and send the username and password to your AppDynamics Administrator, who will need these credentials to integrate Cisco AppDynamics with the Splunk.
In the Assign roles section, assign the user the role you created or updated in Create or Select a Role.