Sets the Layer 7 Metadata Event Exporter protocol parameters on the Network Security appliance that enable connection to the Splunk Enterprise server.
Note
You cannot integrate a SmartVision Edition sensor with a Splunk Enterprise server. SmartVision Edition sensors do not support the Layer 7 Metadata Event Exporter feature.
Note
Splunk integration is not supported on the NX x3xx appliances and the NX 10000 appliance.
Syntax
[no] l7metadata-export protocol {UDP | TCP | HTTPS } ip <ipaddress> port <port number> authorization-header <authorization-header>
Parameters
Specifies the protocol to send Layer 7 metadata events to the Splunk Enterprise server. Sets the destination IPv4 address of the Splunk Enterprise server. The port that the appliance uses to initiate a connection with the Splunk Enterprise server. Valid values are integers ranging from 514 to 65535.The authorization header creates HTTPS event collector token on the Splunk Enterprise server.
Example
The following example sets the Layer 7 Metadata Event Exporter connection parameters to the Splunk Enterprise server over HTTPS.
hostname (config) # l7metadata-export protocol https ip 10.10.10.1 port 8088 authorization-header 2f3f9f46-35b1-42b8-b769-f6f065cedfb6
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.2