09-27-2016 06:23 AM
We would like to see an option to forward user authentication log to sumologic via API.
Currently log forwarding requires an intermediate host to pul the logs from the service via duo API and storing the logs locally, then forwarding.
We would like to eliminate the dependency on an intermediate host.
09-27-2016 08:14 AM
Hey avs,
This seems like a Sumologic feature request. Splunk has this ability. http://blogs.splunk.com/2013/06/18/getting-data-from-your-rest-apis-into-splunk/
I would start here: https://help.sumologic.com/Start_Here/Getting_Started/Get_Help#Feature_Request
Cheers
09-27-2016 07:03 PM
duosec does not have any ability to forward syslog messages.
09-28-2016 07:17 AM
Hey avs,
Perhaps I misunderstood, I thought you meant using the Duo Admin API to pull logs from the service as described here: https://duo.com/docs/adminapi
Are you talking about logs from Authentication Proxy? Those logs have some configurability - https://duo.com/docs/authproxy_reference#main-section -but are going to be logged locally. For those logs, they will need to go from the AP host and be shipped out to Sumologic as you describe.
Cheers
09-28-2016 03:16 PM
can I forward the logs from Duo to Sumlogic via https?
https://help.sumologic.com/Send_Data/Sources/HTTP_Source/Upload_Data_to_an_HTTP_Source
other alternative is syslog forwarding:
https://help.sumologic.com/Beta/Beta_-Sources/Beta-_Cloud_Syslog_Source
10-03-2016 07:17 AM
Hey avs,
Looking at the docs here: http://blogs.splunk.com/2013/06/18/getting-data-from-your-rest-apis-into-splunk/
REST Modular Input is the one you are after. Here are the details you can use to get it all working: https://duo.com/docs/adminapi#api-details
Cheers
10-05-2016 01:34 PM
I got the response from SumoLogic:
They have an ability to run a script on their side as
described at https://help.sumologic.com/Send_Data/Sources/Script_Source
this script for log collection can be tailored to for Duo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide