Splunk

The Splunk connector is a Palantir-provided driver for Splunk.

To create a new Splunk source, follow the standard setup flow for Palantir-provided drivers, then use the sections below for Splunk-specific configuration and networking. For the complete property reference, see the official Splunk driver documentation ↗.

Supported capabilities

CapabilityStatus
Exploration🟢 Generally available
Batch syncs🟢 Generally available
Incremental🟢 Generally available
Table exports🟢 Generally available

Configuration

The properties below are mandatory or recommended.

PropertyRequired?DescriptionDefault
AuthSchemeMandatoryWhether to use Basic Authentication, AccessToken or HTTPEventCollectorToken Authentication when connecting to Splunk.Basic
URLMandatoryThe URL to your Splunk endpoint.https://mySite.splunk.com:{port}
PasswordRecommendedSpecifies the password of the authenticating user account.
UserRecommendedSpecifies the user ID of the authenticating Splunk user account.

Networking

The table below lists the domains that the source must be able to access to run.

For each domain, add a corresponding egress policy. If the source is hosted on-premises and not directly reachable from Foundry, use an agent proxy egress policy instead. The agent host itself must also be able to reach the listed domains. See using an agent as a proxy for details.

DomainRequired
<URL>Always. URL connection property, URL with management port, i.e. https://yoursitename.splunk.com:8089

Table exports

This connector supports table exports. Learn how to set up a table export.