Skip to main content
The Splunk integration allows HiddenLayer to send Supply Chain, Runtime Security, and Audit Log events as datasources to the specified Splunk endpoint.

Prerequisites

To configure the Splunk integration, you need:
  • Administrator access to the HiddenLayer Console (or have an administrator configure it for you).
  • The Splunk HEC endpoint URL and a valid Splunk HEC authentication token.

Configure Splunk

  1. In the HiddenLayer Console, go to Settings > Integrations.
  2. Under Webhooks & Security Tools for Splunk, click the menu (three vertical dots).
  3. Select Configure Integration.
  4. Enter a unique name for the integration.
  5. Enter the Splunk HEC URL and the HEC authentication token.
  6. To disable TLS verification, select the Disable TLS Verification checkbox.
Disabling TLSDisabling TLS verification removes HTTPS security, exposing data to potential interception and tampering. Disabling TLS verification is intended for testing and troubleshooting only
  1. Click next
  2. Select the desired data sources.
  1. Click Submit.

Disable Splunk

You can disable the Splunk integration without deleting its configuration.
  1. In the HiddenLayer Console, go to Settings > Integrations.
  2. Under Webhooks & Security Tools for Splunk, click the menu (three vertical dots).
  3. Click Configure Integration.
  4. Clear the Enabled checkbox.
  5. Click Submit.

Delete Splunk

You can delete the Splunk integration when it is no longer needed.
  1. In the HiddenLayer Console, go to Settings > Integrations.
  2. Click the Splunk menu (three vertical dots).
  3. Select Delete.
  4. Confirm the deletion.