Installation
For Splunk Enterprise
Download the ClickHouse Cloud Audit Add-on for Splunk from Splunkbase. In Splunk Enterprise, navigate to Apps -> Manage. Then click on Install app from file. Select the archived file downloaded from Splunkbase and click on Upload. If everything goes fine, you should now see the ClickHouse Audit logs application installed. If not, consult the Splunkd logs for any errors.Modular input configuration
To configure the modular input, you’ll first need information from your ClickHouse Cloud deployment:- The organization ID
- An admin API Key
Getting information from ClickHouse Cloud
Log in to the ClickHouse Cloud console. Navigate to your Organization -> Organization details. There you can copy the Organization ID. Then, navigate to API Keys from the left-end menu. Create an API Key, give a meaningful name and selectAdmin privileges. Click on Generate API Key.
Save the API Key and secret in a safe place.