Skip to content

Splunk Integration

The Splunk integration allows HiddenLayer to send Supply Chain, Runtime Security, and Audit Log events as datasources to the specified Splunk endpoint.

Prerequisites

To configure the Splunk integration, you need:

  • Administrator access to the HiddenLayer Console (or have an administrator configure it for you).
  • The Splunk HEC endpoint URL and a valid Splunk HEC authentication token.

Configure Splunk

  1. In the HiddenLayer Console, go to Settings > Integrations.

  2. Under Webhooks & Security Tools for Splunk, click the menu (three vertical dots).

    Splunk integration
  3. Select Configure Integration.

  4. Enter a unique name for the integration.

  5. Enter the Splunk HEC URL and the HEC authentication token.

    Splunk integration settings
  6. To disable TLS verification, select the Disable TLS Verification checkbox.

Disabling TLS

Disabling TLS verification removes HTTPS security, exposing data to potential interception and tampering. Disabling TLS verification is intended for testing and troubleshooting only

  1. Click next

  2. Select the desired data sources.

Splunk Data sources
  1. Click Submit.

Disable Splunk

You can disable the Splunk integration without deleting its configuration.

  1. In the HiddenLayer Console, go to Settings > Integrations.

  2. Under Webhooks & Security Tools for Splunk, click the menu (three vertical dots).

  3. Click Configure Integration.

  4. Clear the Enabled checkbox.

    Disable Splunk
  5. Click Submit.

Delete Splunk

You can delete the Splunk integration when it is no longer needed.

  1. In the HiddenLayer Console, go to Settings > Integrations.

  2. Click the Splunk menu (three vertical dots).

  3. Select Delete.

    Delete Splunk
  4. Confirm the deletion.