Additional Configurations
Additional Configurations are available under the Administration menu within the Configuration page.
License
Administrators can manage License Keys under the License tab. Press Add License to add a new license key.
If the license is valid, a green tag is shown.
To delete a license, press the Delete button.
Installed licenses are stored under local/datapunctum_licenses.conf
Proxy
Notifications and Tag updates can initiate HTTP Requests. Use the proxy settings to configure if these requests should pass a proxy server.
The following URLs are accessed by AME:
-
CVE Tag Download:
https://www.cve.org/CVERecord?id={cve} -
Mitre Att&ck Tags:
https://github.com/mitre/cti/raw/master/enterprise-attack/enterprise-attack.json
Hardening
IP Binding
AME supports IP address binding of the splunkd process by setting the SPLUNK_BINDIP environment variable.
PYTHONHTTPSVERIFY
AME supports the PYTHONHTTPSVERIFY setting in splunk-launch.conf