Splunk Subscription

Requirements

Creating a Splunk Subscription

  1. Navigate to Splunk integrations by clicking the Splunk link on the integrations page.

  2. Click the + SUBSCRIPTION button to begin the creation process.

  3. Choose a name for the subscription as well as the saved filters you would like the subscription to be based on.

  4. Choose the connection for the subscription output.

  5. Enter the Splunk index.

  6. Enter a Splunk source type.

  7. Click SAVE

BluBracket events matching your filters will create events in the specified Splunk index.

Edit this page on GitHub

Related docs