# Splunk Integration

The Splunk integration allows HiddenLayer to send Supply Chain, Runtime Security, and Audit Log events as datasources to the specified Splunk endpoint.

## Prerequisites

To configure the Splunk integration, you need:

- Administrator access to the HiddenLayer Console (or have an administrator configure it for you).
- The Splunk HEC endpoint URL and a valid Splunk HEC authentication token.


## Configure Splunk

1. In the HiddenLayer Console, go to **Settings > Integrations**.
2. Under Webhooks & Security Tools for Splunk, click the menu (three vertical dots).

3. Select **Configure Integration**.
4. Enter a unique name for the integration.
5. Enter the Splunk HEC URL and the HEC authentication token.

6. To disable TLS verification, select the Disable TLS Verification checkbox.


Disabling TLS
Disabling TLS verification removes HTTPS security, exposing data to potential interception and tampering. Disabling TLS verification is intended for testing and troubleshooting only

1. Click next
2. Select the desired data sources.


Splunk Data sources
1. Click **Submit**.


## Disable Splunk

You can disable the Splunk integration without deleting its configuration.

1. In the HiddenLayer Console, go to **Settings > Integrations**.
2. Under Webhooks & Security Tools for Splunk, click the menu (three vertical dots).
3. Click **Configure Integration**.
4. Clear the **Enabled** checkbox.

5. Click **Submit**.


## Delete Splunk

You can delete the Splunk integration when it is no longer needed.

1. In the HiddenLayer Console, go to **Settings > Integrations**.
2. Click the Splunk menu (three vertical dots).
3. Select **Delete**.

4. Confirm the deletion.