View all your XDR data directly on the Splunk dashboard.
The following instructions are based on the Splunk Server Enterprise 8.2.3 release. The Splunk settings may be different if you are using a different version of Splunk. Refer to the Splunk documentation for specific information related to your version.
If you are installing the Splunk app as an upgrade, the app automatically applies any valid settings from the old version and disables the Splunk Data inputs settings.
Endpoint URL
Authentication token
Under Status, click the toggles to enable or disable data inputs.
Use the edit icon () to configure data input settings.
The Observed Attack Techniques data input synchronizes events with a risk level equal to or higher than the one specified in the data input settings. Selecting a risk level below medium may increase the amount of data transferred.
After successfully installing the Splunk app, Splunk begins pulling XDR data from Trend Vision One. The app does not pull preexisting XDR data from Trend Vision One. You may need to allow some time before new XDR data starts to appear.