To proceed, ensure you have an active FalconFeeds account. If you don’t have one, create a free account.
What You’ll Do
1
Set up an HTTP Event Collector (HEC) in Splunk
Create and configure a HEC token in your Splunk instance to accept incoming threat feed events.
2
Connect Splunk HEC to FalconFeeds
Add your Splunk HEC URL and token in your FalconFeeds dashboard under Settings → Integrations → Splunk HEC.
3
Test and manage your integration
Verify the integration is working correctly and update or remove it as needed.