Add Splunk to PMC

  1. Select Configuration, and then select SIEM Settings.
  2. Select Enable SIEM Integration to turn on the feature.
  3. From the Integration Type list, select Splunk.
  4. Enter the details for your Splunk configuration:
    • Hostname
    • Index
    • Token
  5. Select the data format: CEF - Common Event Format or ECS - Elastic Common Schema.
  6. Click Validate Settings to test the connection to Splunk.
  7. Click Save Settings.