Skip to main content

Configuring the Integration

  1. In your FalconFeeds Dashboard, go to Settings → Integrations → Splunk HEC.
Navigating to Splunk HEC integration settings in FalconFeeds
  1. Click Add.
Clicking Add to begin the integration setup
  1. Enter the HEC URL and Token retrieved from your Splunk instance. By default, FalconFeeds sends events with the following HEC attributes: Toggle Use custom HEC attributes to override any of these values.
Entering the HEC URL, token and configuring attributes
  1. Click Save. FalconFeeds will now begin sending new threat feed events directly to your Splunk environment.

Testing the Integration

  1. Click the Test button on your integration card.
Test button on the integration card
  1. Click Run test. FalconFeeds will send a sample threat post to your Splunk environment using the configured values. If the test fails, the corresponding HTTP status code will be displayed.
Running the test and viewing the result