Skip to content

Guides

Ledger records in Splunk

Every ledger record as an OCSF event to your HTTP Event Collector, with the URL and token proven by a test event.

Splunk’s HTTP Event Collector (HEC) takes a token; there is no OAuth for it.

  1. In Splunk, Settings, Data inputs, HTTP Event Collector, make a token. Leave indexer acknowledgement off.
  2. On the Splunk card, give the HEC URL (https://http-inputs-<stack>.splunkcloud.com for Splunk Cloud, or your own https://host:8088), the token, and optionally an index. A test event is sent; nothing is saved unless Splunk answers {"text":"Success","code":0}.

The URL must be https and reachable from the internet: like every outbound call Immiscible makes to an address you type, it refuses private, loopback and internal addresses. Events are sent to /services/collector/event with Authorization: Splunk <token>, sourcetype immiscible:ocsf, batched up to 100 a request.

Sources: HEC endpoints, event format.