Configure: Splunk Enterprise (Destination)
CONFIGURE EACH OF THE DISTRIBUTORS (DESTINATION MEDIATORS)
- Index Name : the name of the Index in Splunk - this needs to be created in advance in Splunk
- Splunk Source Type : this is the value that gets assigned to the Source Type in splunk used for filtering.
- Include Raw Json : Toggle to put the Raw Json in the payload sent to splunk.
- Toggle on for Log Request/Responses
Click here to return to Step-by-Step Configuration Guide
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*