Splunk
Splunk indexes operational and security data at scale, queried with SPL. Antimetal runs SPL searches to find the events behind an alert.
What Antimetal does with Splunk
- Run SPL queries across your indexes
- Investigate security and operational events together
- Correlate events from separate sources into one timeline
- Find the specific event that preceded a failure
Connecting Splunk
Go to Integrations in the Antimetal dashboard and find Splunk.
Click Connect and follow the prompt. Depending on the tool this is either an OAuth handoff or a read-only credential you generate in Splunk and paste into Antimetal.
Once Splunk shows as connected, Antimetal begins pulling from it during investigations. No further configuration is required.
Permissions and access
Antimetal connects over MCP with read-only access and performs no write operations. The exact scopes depend on the credential you issue in the vendor tool — grant read access only.
All tenant data is processed in isolated environments. See security and compliance for details.
Need help?
Contact us via Slack or at support@antimetal.com.