Splunk

With our integration with Splunk, you can configure Verosint to automatically send all threat notifications to your Splunk dashboard.

Steps to set up the Verosint integration with Splunk:

  1. Log in to Verosint and navigate to the workspace settings page.
  2. Click Add next to the Splunk logo on the Threat Notifications card
  3. Fill out the required details
    1. Destination: The Splunk HTTP Event Collector (HEC) endpoint to which Verosint will send threat notifications.
    2. Token: The token generated in your Splunk instance.

📘

HTTP Event Collector URL

Note that the full URL is required here. An example URL for a Splunk instance hosted at splunk.example.com port 8443: https://splunk.example.com:8443/services/collector/event

Splunk Configuration Dialog

Splunk Configuration Dialog