Splunk Integration (SIEM)
This document provides instructions on how to integrate Xint’s audit logs with Splunk.
Configuration Steps
Section titled “Configuration Steps”-
Navigate to Menu: Go to [Settings] -> [SIEM].
-
Start Integration: Click the [Add Integration] button under the Splunk section to enter the configuration screen.
-
Enter Information: Provide the HEC details generated in Splunk.
- HEC URL: Enter the full URL to receive logs (e.g.,
https://<splunk-host>:8088/services/collector/event). - HEC Token: Enter the authentication token issued by Splunk.
- Index: Enter the name of the Splunk index where logs will be stored.

- HEC URL: Enter the full URL to receive logs (e.g.,
-
Test Connection: Click the [Test Connection] button to verify that logs are successfully being sent with the provided information.
-
Complete Integration: Click [Add Integration] to save your settings. Once the configuration is active, audit logs will be forwarded to Splunk in real-time.
SIEM Event Specifications
Section titled “SIEM Event Specifications”For the event specifications transmitted to Splunk, please refer to the Audit Log - Event Specifications section.