Add Splunk to PMC
- Select Configuration, and then select SIEM Settings.
- Select Enable SIEM Integration to turn on the feature.
- From the Integration Type list, select Splunk.
- Enter the details for your Splunk configuration:
- Hostname. Do not include https:// in the hostname.
- Index
- Token
- Select the data format: CIM - Common Information Model or ECS - Elastic Common Schema.
- Click Validate Settings to test the connection to Splunk.
- Click Save Settings.