M ManySignal
MS
SP
Integration

Splunk Integration

Pull Splunk notable events into an AI-triage workflow.

What this integration does

Splunk Enterprise Security meets agentic SOC

Splunk Enterprise Security is a widely deployed SIEM generating high volumes of notable events. ManySignal integrates with Splunk via the REST API and Splunk's KV Store, ingesting notable events, running AI triage against the raw search results, and writing dispositions back as Splunk comments or updating the notable event status.

Notable event ingestion via Splunk REST API

Saved search execution to pull raw SPL context for AI analysis

Entity extraction from notable event fields

Data collected

  • Splunk ES notable events
  • Risk object scores and contributing events
  • SPL search results for contextual investigation
  • Asset and identity lookup results

Actions supported

  • Update Splunk notable event status
  • Add comment to Splunk notable event
  • Suppress Splunk notable event (false positive training)
  • Create Splunk ES incident review entry
  • Trigger Splunk SOAR playbook via API

Getting started

Set up in minutes

  1. 1

    Create a Splunk service account

  2. 2

    Enable Splunk REST API access

  3. 3

    Configure the connector

  4. 4

    Define ingestion polling interval

Splunk Integration: frequently asked questions

Is Splunk Enterprise Security (ES) required?

Splunk ES is required for notable event integration. For raw log forwarding from Splunk to ManySignal, the standard Splunk HTTP Event Collector (HEC) forwarder integration is used instead.

Can ManySignal execute SPL searches?

Yes. When an analyst opens an alert in ManySignal, the platform can execute pre-configured SPL searches against the raw Splunk data to surface additional context without leaving ManySignal.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.