<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication log forwarding to sumologic via API in APIs</title>
    <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884830#M605</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;We would like to see an option to forward user authentication log to sumologic via API.&lt;BR /&gt;
Currently log forwarding requires an intermediate host to pul the logs from the service via duo API and storing the logs locally, then forwarding.&lt;BR /&gt;
We would like to eliminate the dependency on an intermediate host.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 27 Sep 2016 13:23:42 GMT</pubDate>
    <dc:creator>avs1</dc:creator>
    <dc:date>2016-09-27T13:23:42Z</dc:date>
    <item>
      <title>Authentication log forwarding to sumologic via API</title>
      <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884830#M605</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;We would like to see an option to forward user authentication log to sumologic via API.&lt;BR /&gt;
Currently log forwarding requires an intermediate host to pul the logs from the service via duo API and storing the logs locally, then forwarding.&lt;BR /&gt;
We would like to eliminate the dependency on an intermediate host.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 27 Sep 2016 13:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884830#M605</guid>
      <dc:creator>avs1</dc:creator>
      <dc:date>2016-09-27T13:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication log forwarding to sumologic via API</title>
      <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884831#M606</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hey avs,&lt;/P&gt;
&lt;P&gt;This seems like a Sumologic feature request. Splunk has this ability. &lt;A href="http://blogs.splunk.com/2013/06/18/getting-data-from-your-rest-apis-into-splunk/" rel="nofollow noopener"&gt;http://blogs.splunk.com/2013/06/18/getting-data-from-your-rest-apis-into-splunk/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I would start here: &lt;A href="https://help.sumologic.com/Start_Here/Getting_Started/Get_Help#Feature_Request" rel="nofollow noopener"&gt;https://help.sumologic.com/Start_Here/Getting_Started/Get_Help#Feature_Request&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 27 Sep 2016 15:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884831#M606</guid>
      <dc:creator>gleezy1</dc:creator>
      <dc:date>2016-09-27T15:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication log forwarding to sumologic via API</title>
      <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884832#M607</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;duosec does not have any ability to forward syslog messages.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Sep 2016 02:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884832#M607</guid>
      <dc:creator>avs1</dc:creator>
      <dc:date>2016-09-28T02:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication log forwarding to sumologic via API</title>
      <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884833#M608</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hey avs,&lt;/P&gt;
&lt;P&gt;Perhaps I misunderstood, I thought you meant using the Duo Admin API to pull logs from the service as described here: &lt;A href="https://duo.com/docs/adminapi" rel="nofollow noopener"&gt;https://duo.com/docs/adminapi&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Are you talking about logs from Authentication Proxy? Those logs have some configurability - &lt;A href="https://duo.com/docs/authproxy_reference#main-section" rel="nofollow noopener"&gt;https://duo.com/docs/authproxy_reference#main-section&lt;/A&gt; -but are going to be logged locally. For those logs, they will need to go from the AP host and be shipped out to Sumologic as you describe.&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Sep 2016 14:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884833#M608</guid>
      <dc:creator>gleezy1</dc:creator>
      <dc:date>2016-09-28T14:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication log forwarding to sumologic via API</title>
      <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884834#M609</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;can I forward the logs from Duo to Sumlogic via https?&lt;BR /&gt;
&lt;A href="https://help.sumologic.com/Send_Data/Sources/HTTP_Source/Upload_Data_to_an_HTTP_Source" class="onebox" target="_blank" rel="nofollow noopener"&gt;https://help.sumologic.com/Send_Data/Sources/HTTP_Source/Upload_Data_to_an_HTTP_Source&lt;/A&gt;&lt;BR /&gt;
other alternative is syslog forwarding:&lt;BR /&gt;
&lt;A href="https://help.sumologic.com/Beta/Beta_-" rel="nofollow noopener"&gt;https://help.sumologic.com/Beta/Beta_-&lt;/A&gt;&lt;EM&gt;Sources/Beta&lt;/EM&gt;-_Cloud_Syslog_Source&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Sep 2016 22:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884834#M609</guid>
      <dc:creator>avs1</dc:creator>
      <dc:date>2016-09-28T22:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication log forwarding to sumologic via API</title>
      <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884835#M610</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hey avs,&lt;/P&gt;
&lt;P&gt;Looking at the docs here: &lt;A href="http://blogs.splunk.com/2013/06/18/getting-data-from-your-rest-apis-into-splunk/" rel="nofollow noopener"&gt;http://blogs.splunk.com/2013/06/18/getting-data-from-your-rest-apis-into-splunk/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;REST Modular Input is the one you are after. Here are the details you can use to get it all working: &lt;A href="https://duo.com/docs/adminapi#api-details" rel="nofollow noopener"&gt;https://duo.com/docs/adminapi#api-details&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 03 Oct 2016 14:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884835#M610</guid>
      <dc:creator>gleezy1</dc:creator>
      <dc:date>2016-10-03T14:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication log forwarding to sumologic via API</title>
      <link>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884836#M611</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;I got the response from SumoLogic:&lt;BR /&gt;
They have an ability to run a script on their side as&lt;BR /&gt;
described at &lt;A href="https://help.sumologic.com/Send_Data/Sources/Script_Source" rel="nofollow noopener"&gt;https://help.sumologic.com/Send_Data/Sources/Script_Source&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;this script for log collection can be tailored to for Duo&lt;BR /&gt;
&lt;/P&gt;&lt;ASIDE class="onebox whitelistedgeneric"&gt;
  &lt;HEADER class="source"&gt;
      &lt;IMG src="https://github.githubassets.com/favicons/favicon.svg" class="site-icon" width="32" height="32" /&gt;
      &lt;A href="https://github.com/RobsRepo/Collecting-Okta-Event-Logs" target="_blank" rel="nofollow noopener"&gt;GitHub&lt;/A&gt;
  &lt;/HEADER&gt;
  &lt;ARTICLE class="onebox-body"&gt;
    &lt;IMG src="https://avatars0.githubusercontent.com/u/9926522?s=400&amp;amp;v=4" class="thumbnail onebox-avatar" width="300" height="300" /&gt;

&lt;H3&gt;&lt;A href="https://github.com/RobsRepo/Collecting-Okta-Event-Logs" target="_blank" rel="nofollow noopener"&gt;RobsRepo/Collecting-Okta-Event-Logs&lt;/A&gt;&lt;/H3&gt;

&lt;P&gt;A Python script to collect event logs from Okta. Contribute to RobsRepo/Collecting-Okta-Event-Logs development by creating an account on GitHub.&lt;/P&gt;


  &lt;/ARTICLE&gt;
  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;
  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;
&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 05 Oct 2016 20:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/authentication-log-forwarding-to-sumologic-via-api/m-p/4884836#M611</guid>
      <dc:creator>avs1</dc:creator>
      <dc:date>2016-10-05T20:34:34Z</dc:date>
    </item>
  </channel>
</rss>

