Skip to main content
To proceed, ensure you have an active FalconFeeds account. If you don’t have one, create a free account.

What You’ll Do

1

Set up an HTTP Event Collector (HEC) in Splunk

Create and configure a HEC token in your Splunk instance to accept incoming threat feed events.
2

Connect Splunk HEC to FalconFeeds

Add your Splunk HEC URL and token in your FalconFeeds dashboard under Settings → Integrations → Splunk HEC.
3

Test and manage your integration

Verify the integration is working correctly and update or remove it as needed.