Skip to main content

Splunk

Use a Splunk alert action (webhook):

  1. In your saved search / alert: Trigger actions → Webhook
  2. URL: https://skylogs.example.com/api/v1/ingest/splunk/<token>

Useful for SOC workflows: route security alerts to a security team with its own escalation policy, separate from infrastructure alerting.