Guides
Ledger records in Splunk
Every ledger record as an OCSF event to your HTTP Event Collector, with the URL and token proven by a test event.
Splunk’s HTTP Event Collector (HEC) takes a token; there is no OAuth for it.
- In Splunk, Settings, Data inputs, HTTP Event Collector, make a token. Leave indexer acknowledgement off.
- On the Splunk card, give the HEC URL (
https://http-inputs-<stack>.splunkcloud.comfor Splunk Cloud, or your ownhttps://host:8088), the token, and optionally an index. A test event is sent; nothing is saved unless Splunk answers{"text":"Success","code":0}.
The URL must be https and reachable from the internet: like every outbound call Immiscible makes to an address you type, it refuses private, loopback and internal addresses. Events are sent to /services/collector/event with Authorization: Splunk <token>, sourcetype immiscible:ocsf, batched up to 100 a request.
Sources: HEC endpoints, event format.