17.1 Configuring Splunk for Integration

Splunk must be able to receive the data coming from Secure Configuration Manager.

  1. Log in to Splunk.

  2. For TCP/UDP, create an instance for a TCP or UDP listener with syslog source type.

  3. Specify the Port you want to use to receive data from Secure Configuration Manager.

  4. Specify values for Source name override and Only accept connection from, as needed.

  5. To verify the data is correct, check whether the TCP Data inputs table lists your new syslog source.