14.2. Using the Red Hat Advanced Cluster Security for Kubernetes add-on


You can use the Red Hat Advanced Cluster Security for Kubernetes add-on to forward the vulnerability detection and compliance related data from the Red Hat Advanced Cluster Security for Kubernetes to Splunk.

Generate an API token with read permission for all resources in Red Hat Advanced Cluster Security for Kubernetes and then use that token to install and configure the add-on.

14.2.1. Installing and configuring the Splunk add-on

You can install the Red Hat Advanced Cluster Security for Kubernetes add-on from your Splunk instance.

참고

To maintain backward compatibility with the StackRox Kubernetes Security Platform add-on, the source_type and input_type parameters for configured inputs are still called stackrox_compliance, stackrox_violations, and stackrox_vulnerability_management.

Prerequisites

  • You must have an API token with read permission for all resources of Red Hat Advanced Cluster Security for Kubernetes. You can assign the Analyst system role to grant this level of access. The Analyst role has read permissions for all resources.

Procedure

  1. Download the Red Hat Advanced Cluster Security for Kubernetes add-on from Splunkbase.
  2. Go to the Splunk home page on your Splunk instance.
  3. Go to Apps Manage Apps.
  4. Select Install app from file.
  5. In the Upload app pop-up box, select Choose File and select the Red Hat Advanced Cluster Security for Kubernetes add-on file.
  6. Click Upload.
  7. Click Restart Splunk, and confirm to restart.
  8. After Splunk restarts, select Red Hat Advanced Cluster Security for Kubernetes from the Apps menu.
  9. Go to Configuration and then click Add-on Settings.

    1. For Central Endpoint, enter the IP address or the name of your Central instance. For example, central.custom:443.
    2. Enter the API token you have generated for the add-on.
    3. Click Save.
  10. Go to Inputs.
  11. Click Create New Input, and select one of the following:

    • ACS Compliance to pull the compliance data.
    • ACS Violations to pull the violations data.
    • ACS Vulnerability Management to pull the vulnerabilities data.
  12. Enter a Name for the input.
  13. Select an Interval to pull data from Red Hat Advanced Cluster Security for Kubernetes. For example, every 14400 seconds.
  14. Select the Splunk Index to which you want to send the data.
  15. For Central Endpoint, enter the IP address or the name of your Central instance.
  16. Enter the API token you have generated for the add-on.
  17. Click Add.

Verification

  • To verify the the Red Hat Advanced Cluster Security for Kubernetes add-on installation, query the received data.

    1. In your Splunk instance, go to Search and type index=* sourcetype="stackrox-*" as the query.
    2. Press Enter.

Verify that your configured sources are displayed in the search results.

14.2.2. Update the StackRox Kubernetes Security Platform add-on

If you are using the StackRox Kubernetes Security Platform add-on, you must upgrade to the new Red Hat Advanced Cluster Security for Kubernetes add-on.

You can see the update notification on the Splunk homepage under the list of apps on the left. Alternatively, you can also go to the Apps Manage apps page to see the update notification.

Prerequisites

  • You must have an API token with read permission for all resources of Red Hat Advanced Cluster Security for Kubernetes. You can assign the Analyst system role to grant this level of access. The Analyst role has read permissions for all the resources.

Procedure

  1. Click Update on the update notification.
  2. Select the checkbox for accepting the terms and conditions, and then click Accept and Continue to install the update.
  3. After the installation, select Red Hat Advanced Cluster Security for Kubernetes from the Apps menu.
  4. Go to Configuration and then click Add-on Settings.

    1. Enter the API token you have generated for the add-on.
    2. Click Save.

14.2.3. Troubleshoot the Splunk add-on

If you stop receiving events from the Red Hat Advanced Cluster Security for Kubernetes add-on, check the Splunk add-on debug logs for errors.

Splunk creates a debug log file for every configured input in the /opt/splunk/var/log/splunk directory. Find the file named stackrox_<input>_<uid>.log, for example, stackrox_compliance_29a3e14798aa2363d.log and look for issues.

Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 문서 정보

Legal Notice

Theme

© 2026 Red Hat
맨 위로 이동