Splunk integration
The splunk.notify rule action sends a matched rule alert and its cited
fully qualified domain names (FQDNs) to Splunk HTTP Event Collector (HEC).
The rule decides which events trigger the action. There is no additional
classification or tag filter. Connecting Splunk alone does not export findings.
- In Splunk, create an HEC token that can write to the intended index. Keep indexer acknowledgement off on the token unless using Enterprise acknowledgement in this connector.
- In the app, open Connectors > Splunk Enterprise and Cloud.
- Enter the HEC endpoint, deployment, optional index, source, sourcetype, and token.
- Select Enterprise acknowledgement only for Splunk Enterprise.
- Select Save to store the configuration.
- Select Test connection to verify the saved configuration and enable export.
- Arrange for an enabled
splunk.notifyaction on each intended rule and Splunk connection.
The endpoint must be public HTTPS and use port 443 or 8088. Enter either the
HEC base path or /services/collector/event. The setup page does not display
the saved token. Leave the token blank to keep it when updating the same
endpoint. Changing the endpoint requires entering a token. Saving another token
replaces it for the same connection.
Saving does not send a test event. The saved connection remains inactive until Test connection succeeds. Save any configuration changes before testing. If a test fails, the configuration stays saved and export remains inactive.
Delivery semantics
Section titled “Delivery semantics”An enabled splunk.notify action sends a matched rule alert only when the
Splunk connection is enabled and connected and its HEC destination is enabled.
Each finding has a stable event_id equal to the rule alert ID.
Each configured action makes at most one delivery attempt for an alert. Failures before delivery starts may be retried, but the event is not resent after delivery starts. A service interruption can therefore lose an export. If the provider response is lost, the outcome is unknown because HEC might already have accepted the event. Historical backfill and automatic replay are not available.
The setup page shows the last connection-test result, not live delivery health.
Matched FQDNs
Section titled “Matched FQDNs”finding.fqdns is a sorted, deduplicated array resolved from the alert’s cited
source records:
- Domain references contribute the matched domain names.
- Email references contribute sender-from, envelope-sender, and URL domains.
- Canary references contribute the hostnames where the canary was observed.
Only records cited by the alert contribute to the array. Hostnames are normalized without collapsing subdomains. Missing records and invalid hostname values are omitted; an alert with no available FQDNs has an empty array. A retrieval failure skips the Splunk action instead of reporting an empty result.
The array reflects the references retained by the alert, currently at most ten per source. It is not an exhaustive inventory beyond that evidence sample.
Event format
Section titled “Event format”HEC receives a JSON envelope like this. The event object is the product
payload; time, source, sourcetype, and optional index are HEC metadata.
{ "time": 1789714361, "source": "haveibeensquatted:response-plane", "sourcetype": "haveibeensquatted:response:v1", "index": "security", "event": { "schema_version": 1, "event_id": "d16b752d-3d3b-4e72-bc6f-cfd12112f0b4", "event_type": "finding.created", "finding": { "id": "d16b752d-3d3b-4e72-bc6f-cfd12112f0b4", "domain_id": "c2b351e1-7bd5-401d-9b42-5c3f3a17542b", "lookup_id": "1c5804dd-86ec-42c9-bce3-8b456c937936", "rule_id": "1af143cb-34dd-4cac-9c58-2aa0bbd181f0", "title": "Possible impersonation", "level": "high", "alert_status": "active", "created_on_unix": 1789714361, "fqdns": ["login-example.test", "mail.login-example.test"] } }}Acknowledgements
Section titled “Acknowledgements”With acknowledgement disabled, a successful test or delivery means HEC accepted the event. This does not prove that Splunk indexed it, that a search can see it, or that an analyst acted on it.
With Splunk Enterprise acknowledgement enabled, delivery makes up to five HEC
acknowledgement checks within a ten-second budget, separate from the event
submission timeout. The connection test makes one acknowledgement request with
a ten-second timeout. An acknowledged result means Splunk reported
replication at the configured factor. It does not guarantee indexing, search
visibility, analyst consumption, or containment. A failed or pending
acknowledgement check retains the confirmed HEC acceptance outcome.
After this budget is exhausted, acknowledgement checks stop. The event is not
resent and its search visibility remains unverified.
Splunk Cloud configuration always disables generic HEC acknowledgement mode. Splunk documents Amazon Data Firehose as the supported acknowledgement sender for Splunk Cloud.