Adding Splunk Integrations
A Splunk integration forwards events from Veeam Data Cloud to a Splunk instance through the HTTP Event Collector (HEC). You can then search, correlate and visualize these events alongside other security data in your SIEM.
Before you add a Splunk integration, ensure that the HTTP Event Collector is enabled in your Splunk instance and that a HEC token has been generated. You need the HEC endpoint URL and the token value to complete the procedure. For details on HEC in Splunk Web, see Splunk Documentation.
To add a Splunk integration, do the following:
- Click the settings icon in the top-right corner.
- Select Integrations.
- On the Integrations tab, click Add Integration.
- In the Select Integration window, select Splunk and click Continue.
- In the Connector Name field, specify a name for the integration.
- In the Destination URL field, specify the HEC endpoint URL of your Splunk instance, for example, https://http-inputs-yourdomain.splunkcloud.com/services/collector/event.
- In the Splunk HEC Token field, enter the HEC token generated in Splunk. The token is stored securely and masked when you view the integration later.
- [Optional] In the Event Rules section, click Add Rules to define which event types and properties to forward and how to format them. If you do not add any rules, Veeam Data Cloud forwards raw events. For details on configuring event rules, see Configuring Event Rules.
- To verify your settings, click Test Connection. Veeam Data Cloud will send a test event to the specified destination.
- Click Add to save the integration.
