# Splunk Integration

This integration ensures that your team stays informed about important changes and potential security risks & threats within your environment, enhancing your organization's identity protection capabilities.

### Configuring Splunk HTTP Event Collector

For the integration, you will need an HTTP Event collector configured in Splunk. information regarding the process can be found on [Splunk documentation](https://docs.splunk.com/Documentation/Splunk/9.0.4/Data/UsetheHTTPEventCollector). After performing the steps as described in their documentation, please keep note of the Webhook URL and Authorization Token.

### Adding integration in Rezonate

To enable this integration, click the setting button on the top right corner of the application.\
In the settings, select Accounts & Integrations, and then pick **External Integrations**.

Click on **New Integration** and select **Splunk**.

**Fill out the form as follows:**

<table data-header-hidden><thead><tr><th width="148"></th><th></th></tr></thead><tbody><tr><td><strong>Property</strong></td><td><strong>Value</strong></td></tr><tr><td>Name</td><td>Select your integration name.</td></tr><tr><td>URL</td><td><p>If you are using <strong>Splunk Cloud</strong> please write:</p><pre><code><strong>https://http-inputs-{$SPLUNK_TENANT_NAME}.splunkcloud.com/services/collector/raw
</strong></code></pre><p>You can extract your Splunk <strong>SPLUNK_TENANT_NAME</strong> from the Url being used to access the application https://<strong>mydomain</strong>.splunkcloud.com (the bold part)</p><p> </p><p>If you are using <strong>Self</strong>-<strong>managed</strong> <strong>Splunk</strong> please write:</p><pre><code><strong>https://{$SPLUNK_DOMAIN$}:{$SPLUNK_HEC_PORT}/services/collector/raw
</strong></code></pre></td></tr><tr><td>Authorization Token</td><td>Please write down the Secret Token you received from Splunk during the creation process. </td></tr></tbody></table>

Note that before saving the integration, you can click on **Test Integration** which will send an example message to that channel.

<figure><img src="https://2355086414-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIkSba0W4HlnmPJ93gVOS%2Fuploads%2F6mpwtmkbsCGSVYieBawq%2Fimage.png?alt=media&#x26;token=d573f8d1-e07e-4b51-8242-83e6a25eb890" alt=""><figcaption><p>Splunk integration screen, Rezonate Platform.</p></figcaption></figure>

Thats it! now you can send Notifications and Alerts from any part of the platform to Splunk.
