Splunk logo

Splunk

Sync Splunk events, searches, and index data into your warehouse.

Overview

The Splunk connector syncs your observability data into analytics-ready tables in your data warehouse. Pull events, searches, and indexes from the Splunk REST API, with Ingest handling auth, pagination, and retries so the tables stay current.

What you can sync

Ingest syncs the following Splunk data into your data warehouse, each as its own table refreshed on your schedule:

  • Events
  • Searches
  • Indexes

Authentication

API token (Bearer)

Create a token in Splunk Web under Settings > Tokens and send it as an Authorization: Bearer header.

You enter credentials in a secure form, never in chat. Ingest stores and rotates them for you.

Resources