splunk data.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Splunk

{% hint style="info" %} Splunk is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. {% endhint %}

The Dropzone platform integrates with the Splunk security SIEM. Many customers ingest other alert sources into Splunk (e.g. IDPs) and integrate Dropzone into Splunk rather than the source systems.

Dropzone communicates to Splunk Enterprise using the Dropzone Connector.

There are two methods to integrate with Dropzone AI: creating a Splunk User or configuring an API token. To create an API token, follow instructions in Splunk's documentation.

Create a Splunk User

To create a Splunk user, do the following:

Navigate to Users

Click New User

{% hint style="info" %} You may need to add capabilities to this role depending on the level of access you want Dropzone to have. If you would like to limit the indexes Dropzone has access to, you will need to create a custom role with inherited permissions from the user role. See the Splunk documentation for more information on creating custom roles. {% endhint %}

Fill out fields for New User

Create new user

Enable Splunk

To enable the Data Source integration, you'll need the following information:

Dropzone Field Source
Server The hostname or IP address of your Splunk server, e.g splunk.corp.example.net
Password The username of the Splunk user you created earlier
Password The password of the Splunk user you created earlier

{% hint style="info" %} If you chose to create an API token instead of a Splunk user, you will need to use the API token instead. {% endhint %}

To enable the Data Source integration, do the following:

Integrations Dropdown

Click Available

The Splunk Tile

The Splunk Data Source Configuration (pt 1)

The Splunk Data Source Configuration (pt 2)

The Splunk Data Source Configuration (pt 3)

The Splunk Data Source Configuration (pt 4)

The Splunk Data Source Configuration (pt 5)

The Splunk Data Source Configuration (pt 6)

If you have any errors or questions, engage your Dropzone AI support representative.