Overview
The Splunk connector syncs your observability data into analytics-ready tables in your data warehouse. Pull events, searches, and indexes from the Splunk REST API, with Ingest handling auth, pagination, and retries so the tables stay current.
What you can sync
Ingest syncs the following Splunk data into your data warehouse, each as its own table refreshed on your schedule:
- Events
- Searches
- Indexes
Authentication
API token (Bearer)
Create a token in Splunk Web under Settings > Tokens and send it as an Authorization: Bearer header.
You enter credentials in a secure form, never in chat. Ingest stores and rotates them for you.
Resources
Splunk API docs ↗
Official provider documentation.
Authentication
How Ingest stores and rotates credentials.
Request access
Tell us you want this connector and we will get you set up.
Don't see the endpoint you need? Tell us and we will add it.