14.2. Using the Red Hat Advanced Cluster Security for Kubernetes add-on


You can use the Red Hat Advanced Cluster Security for Kubernetes add-on to forward the vulnerability detection and compliance related data from the Red Hat Advanced Cluster Security for Kubernetes to Splunk.

Generate an API token with read permission for all resources in Red Hat Advanced Cluster Security for Kubernetes and then use that token to install and configure the add-on.

14.2.1. Installing and configuring the Splunk add-on

You can install the Red Hat Advanced Cluster Security for Kubernetes add-on from your Splunk instance.

注記

To maintain backward compatibility with the StackRox Kubernetes Security Platform add-on, the source_type and input_type parameters for configured inputs are still called stackrox_compliance, stackrox_violations, and stackrox_vulnerability_management.

Prerequisites

  • You must have an API token with read permission for all resources of Red Hat Advanced Cluster Security for Kubernetes. You can assign the Analyst system role to grant this level of access. The Analyst role has read permissions for all resources.

Procedure

  1. Download the Red Hat Advanced Cluster Security for Kubernetes add-on from Splunkbase.
  2. Go to the Splunk home page on your Splunk instance.
  3. Go to Apps Manage Apps.
  4. Select Install app from file.
  5. In the Upload app pop-up box, select Choose File and select the Red Hat Advanced Cluster Security for Kubernetes add-on file.
  6. Click Upload.
  7. Click Restart Splunk, and confirm to restart.
  8. After Splunk restarts, select Red Hat Advanced Cluster Security for Kubernetes from the Apps menu.
  9. Go to Configuration and then click Add-on Settings.

    1. For Central Endpoint, enter the IP address or the name of your Central instance. For example, central.custom:443.
    2. Enter the API token you have generated for the add-on.
    3. Click Save.
  10. Go to Inputs.
  11. Click Create New Input, and select one of the following:

    • ACS Compliance to pull the compliance data.
    • ACS Violations to pull the violations data.
    • ACS Vulnerability Management to pull the vulnerabilities data.
  12. Enter a Name for the input.
  13. Select an Interval to pull data from Red Hat Advanced Cluster Security for Kubernetes. For example, every 14400 seconds.
  14. Select the Splunk Index to which you want to send the data.
  15. For Central Endpoint, enter the IP address or the name of your Central instance.
  16. Enter the API token you have generated for the add-on.
  17. Click Add.

Verification

  • To verify the the Red Hat Advanced Cluster Security for Kubernetes add-on installation, query the received data.

    1. In your Splunk instance, go to Search and type index=* sourcetype="stackrox-*" as the query.
    2. Press Enter.

Verify that your configured sources are displayed in the search results.

14.2.2. Update the StackRox Kubernetes Security Platform add-on

If you are using the StackRox Kubernetes Security Platform add-on, you must upgrade to the new Red Hat Advanced Cluster Security for Kubernetes add-on.

You can see the update notification on the Splunk homepage under the list of apps on the left. Alternatively, you can also go to the Apps Manage apps page to see the update notification.

Prerequisites

  • You must have an API token with read permission for all resources of Red Hat Advanced Cluster Security for Kubernetes. You can assign the Analyst system role to grant this level of access. The Analyst role has read permissions for all the resources.

Procedure

  1. Click Update on the update notification.
  2. Select the checkbox for accepting the terms and conditions, and then click Accept and Continue to install the update.
  3. After the installation, select Red Hat Advanced Cluster Security for Kubernetes from the Apps menu.
  4. Go to Configuration and then click Add-on Settings.

    1. Enter the API token you have generated for the add-on.
    2. Click Save.

14.2.3. Troubleshoot the Splunk add-on

If you stop receiving events from the Red Hat Advanced Cluster Security for Kubernetes add-on, check the Splunk add-on debug logs for errors.

Splunk creates a debug log file for every configured input in the /opt/splunk/var/log/splunk directory. Find the file named stackrox_<input>_<uid>.log, for example, stackrox_compliance_29a3e14798aa2363d.log and look for issues.

Red Hat logoGithubredditYoutubeTwitter

詳細情報

試用、購入および販売

コミュニティー

会社概要

Red Hat は、企業がコアとなるデータセンターからネットワークエッジに至るまで、各種プラットフォームや環境全体で作業を簡素化できるように、強化されたソリューションを提供しています。

多様性を受け入れるオープンソースの強化

Red Hat では、コード、ドキュメント、Web プロパティーにおける配慮に欠ける用語の置き換えに取り組んでいます。このような変更は、段階的に実施される予定です。詳細情報: Red Hat ブログ.

Red Hat ドキュメントについて

Legal Notice

Theme

© 2026 Red Hat
トップに戻る