You can enable or disable the Layer 7 Metadata Event Exporter to collect logs generated by the Network Security appliance using the appliance Web UI or CLI:
When you enable the Layer 7 Metadata Event Exporter on the appliance, the appliance sends the network event logs to the Splunk Enterprise server for further analysis. When you disable the Layer 7 Metadata Event Exporter on the appliance, the appliance will not send the network event logs to the Splunk Enterprise server. The Layer 7 Metadata Event Exporter is disabled by default and must be configured and enabled.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Splunk Enterprise server.
Gather the following Splunk Enterprise server configuration parameters: transport protocol, IPv4/IPv6 address, and port.
Understand Splunk interaction with Evidence Collector and Comm Broker. See Using the Layer 7 metadata Event Exporter to send events to a Splunk Enterprise Server.
Create the HTTP Event Collector token on the Splunk Enterprise server. See Creating an HTTP Event Collector token on a Splunk Enterprise Server.