You can configure a SIEM platform (Splunk) using the Network Detection and Response user interface.
Note
The configuration of integrated products is available only to users with an Enterprise or Core license.
Important
The description data appears by default in The Description box. You cannot edit it.
From the main menu, click Integration Hub > Add Integrations and then select SPLUNK.
Specify the integration name.
Specify the IP address or hostname of your SIEM server.
Specify the port on which SIEM is listening for log data.
Specify the HEC token in the Authentication box.
Select the SSL checkbox to enable exporting of events or alerts to splunk over HTTPS.
Select the Notification checkbox to allow notifications for alerts, layer 7 meta-data and flow events to be sent to configured Splunk server. Choose the required notification method and log format. The values are provided by default and cannot be changed. If you want to change the notification method to HTTPS, select the SSL checkbox.
Click Add and Verify Integration.
Based on the data exported to SIEM after saving SIEM integration, stats starts to appear in the UI.
