SFTP To Go
Splunk Cloud
SFTP To Go
SFTP To Go is a fully managed secure, scalable, and reliable cloud file storage service supporting SFTP, FTPS, S3, and HTTPS protocols. It allows sharing and integration with third parties using popular and secure protocols, and automates data management and processing using APIs and webhooks.
- Secure data transfer and transparent encryption at rest
- Reliable offsite backup
- Compatibility and ease of use
Splunk Cloud
Splunk Cloud is a cloud-hosted data platform used to collect, search, analyze, visualize, and alert on machine data, operational logs, and security events. By connecting SFTP To Go with Splunk Cloud, you can stream SFTP To Go audit log events to a Splunk HTTP Event Collector endpoint, then use those events for log search, dashboards, alerts, compliance review, and SIEM workflows.
- Stream SFTP To Go audit log events to a Splunk HTTP Event Collector endpoint
- Search and filter SFTP activity by source, event type, user, IP address, file path, and timestamp
- Use SFTP audit events in Splunk searches, dashboards, alerts, reports, and SIEM workflows
How does it work?
- In Splunk Cloud, confirm that HTTP Event Collector is available and ready for use. Splunk Cloud Platform supports HEC tokens for receiving event data over HTTPS.
- Create or select the Splunk HEC token that SFTP To Go should use for audit log intake. Confirm the index, source type, and allowed index settings for the token before using it in SFTP To Go.
- Copy the Splunk HEC endpoint for your Splunk Cloud environment. SFTP To Go sends audit log events to
<your-HEC-endpoint>/services/collector/event, so the endpoint you enter in SFTP To Go must start withhttps://. - In SFTP To Go, add Splunk Cloud as a streaming audit log destination by following the SFTP To Go documentation for Splunk Cloud destinations. Complete the SFTP To Go destination setup there before continuing with the Splunk search, indexing, dashboard, alerting, and SIEM steps below.
- After the destination is saved in SFTP To Go, generate a test event by performing an auditable action, such as a login, failed login, upload, download, delete, or access-denied attempt.
- In Splunk Cloud, search the index assigned to the HEC token and confirm that the SFTP To Go audit event arrives. Start with a filter for
source="sftptogo", then narrow by timestamp, event type, username, IP address, file path, or other fields in the audit event. - Inspect the event payload in Splunk. SFTP To Go wraps each audit event in the Splunk HEC envelope, and the
eventfield carries the SFTP To Go audit log object. Thesourcevalue issftptogo, and thetimefield is the event timestamp in Unix seconds with fractional milliseconds. - Confirm that Splunk is assigning the expected index, source, source type, and timestamp to the incoming events. The HEC token configuration controls how Splunk Cloud indexes the events, so correct these settings if searches do not return the expected SFTP To Go audit records.
- Create field extractions or search-time field handling only where needed. Useful fields for investigation can include event type, principal type, username, session ID, source IP address, location, user agent, file path, timestamp, and event-specific data.
- Create saved searches for high-priority SFTP To Go security events. Useful starting points include repeated failed logins, access-denied events, unexpected downloads, delete activity, access from unfamiliar locations, or spikes in file activity over a short time window.
- Create alerts from the saved searches that require immediate review. Route alerts according to your internal process, such as email, ticketing, on-call notification, or a security operations workflow.
- Build dashboards or reports for common SFTP To Go investigations. For example, create views for recent failed logins, file deletes, high-volume downloads, access-denied events, activity by user, activity by IP address, and file activity over time.
- If you use Splunk as part of a SIEM workflow, map SFTP To Go audit events into the searches, correlation rules, notable events, or investigation views your security team already uses. Treat the SFTP To Go events as Splunk-indexed audit logs from managed SFTP activity.
- Test the complete workflow by triggering each important event type in SFTP To Go and confirming that it appears in Splunk Cloud with the expected source, timestamp, index, searchable fields, dashboards, saved searches, and alerts.
- Monitor delivery health in SFTP To Go and HEC intake behavior in Splunk Cloud. If events stop arriving, check the SFTP To Go destination status, HEC endpoint, HEC token validity, token deployment status, index permissions, source type settings, and any search or index filters that could prevent expected events from appearing.
- As your security monitoring requirements change, update your Splunk indexes, source type handling, field extractions, saved searches, dashboards, alerts, and SIEM rules without changing the underlying SFTP To Go file transfer environment.
Ready to get started?
Be up and running with your secure cloud storage in seconds
Get started with a free trial