{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition","img"]},"type":"markdown"},"seo":{"title":"Integrating Coro with Splunk","description":"Coro's support and product documentation portal","siteUrl":"https://docs.coro.net","keywords":"Coro docs portal, documentation, support, docs","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"integrating-coro-with-splunk","__idx":0},"children":["Integrating Coro with Splunk"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this guide to integrate Coro with Splunk (",{"$$mdtype":"Tag","name":"a","attributes":{"href":"https://www.splunk.com/en_us/products/enterprise-security.html"},"children":["www.splunk.com/en_us/products/enterprise-security.html"]},") for collection of ticket data related to an event."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro sends SIEM data to Splunk via HTTP event collector (HEC) REST API endpoints."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Disable ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enable indexer acknowledgment"]}," when configuring an HEC on the Splunk Cloud Platform:"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/add-connector-splunk-hec-enable-indexer-ack.d31df170f1f0fdb728d7943f9f6c9b24162472a7a7cc54f1e7ec86ddda984650.dd802eb3.png","alt":"Enable Indexer Acknowledgment","withLightbox":true,"width":"500px"},"children":[]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"configuring-a-splunk-connector","__idx":1},"children":["Configuring a Splunk connector"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To configure a Splunk connector:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"a","attributes":{"href":"/overview/log-in"},"children":["Sign in to the Coro console"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From the sidebar, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Control Panel"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Workspace"]},", select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connectors"]},":"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/control-panel-connectors.ab41a5d9d3f0ae20478980f5a9f2c3653fd655b06443719e582eb3595d0c44ad.dd802eb3.png","alt":"Connectors","withLightbox":true},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro displays the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connectors"]}," page."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SIEM"]},":"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/connectors-page.6aea1944597a5cbd37790445ec617189c55f4555928346f13398eea86f750017.dd802eb3.png","alt":"The Connectors page","withLightbox":true},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ADD CONNECTOR"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro displays the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add connector"]}," dialog:"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/add_connector_dialog.0a99bdd42f419f2803deee0567d1e0060b936b20826a37b45dda84f858c82802.dd802eb3.png","alt":"The Add connector dialog","withLightbox":true},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Configure the following connection settings:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]},": Enter a suitable connector name."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Format"]},": Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Splunk"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Listener URL"]},": Enter the URL endpoint provided by your SIEM platform."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Listener URL"]}," must be in the format: ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["http(s)://Public IP Address of Splunk/services/collector"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Example value: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://192.0.2.0:8088/services/collector"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Listener URL"]}," must match the SSL configuration (",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enable SSL"]}," option) in your Splunk cloud platform HEC settings:"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/add-connector-splunk-hec-enable-ssl.0c006f7e3554821dcb73050fc0d54f089363b480404ef56c5522cb2f722bc0c6.dd802eb3.png","alt":"SSL configuration","withLightbox":true,"width":"500px"},"children":[]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enable SSL"]}," is enabled, use ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["https://"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enable SSL"]}," is disabled, use ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["http://"]}]}]}]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/connectors_config_splunk-ssl-config.93793b166fdb049ff5f3962cdda49d0916ac510357eae7da0a251baa462ca45b.dd802eb3.png","alt":"SSL configuration","withLightbox":true,"width":"500px"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The port number part of the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Listener URL"]}," must match the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["HTTP Port Number"]}," value in your Splunk cloud platform HEC settings:"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/add-connector-splunk-hec-port-number.d7d00b947da7943dcd3083099f1c6209fd5d60da3b48cba8b532f8bad2f6276b.dd802eb3.png","alt":"HTTP Port Number","withLightbox":true,"width":"500px"},"children":[]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/connectors_config_splunk-port-config.4a1821fe9a9e46e0845af77d6fcecd996e478e80d62c3ffefec46bae1199f83b.dd802eb3.png","alt":"HTTP Port Number","withLightbox":true,"width":"500px"},"children":[]}]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization"]},": Enter the authorization header provided by your SIEM platform."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization"]}," header must be in the format: ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Splunkf <Authorization_token>"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Example value: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Splunkf 9b30ab7-85bf-4dd5-8fd9-b42bb3a74163"]},"."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Apply to all customers"]},": (MSP admin users only) Enable this option to automatically create the connector in all descendant workspaces linked to the channel workspace. Each descendant workspace then forwards events to the configured SIEM provider."]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ADD"]},"."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/connectors_apply_to_all.9046a5213ef4873202d31e1b054d432835a3eeda3ededd9b01e77af1367c6d8c.dd802eb3.png","alt":"Add Splunk connector","withLightbox":true,"width":"600px"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro sends a test event to verify your configuration. If the configuration is incorrect, Coro displays an error dialog. Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["GOT IT"]}," to return to the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connectors"]}," page. Coro does not save the configuration:"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/connector-error-generic.3a5ebeec01928944ea2977163ac4cc1860cb89164e1cf6ec4ec3748d272a7b49.dd802eb3.png","alt":"Invalid connector configuration","withLightbox":true,"width":"350px"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If the configuration is correct, Coro creates the connector with a status of ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connected"]},":"]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/connector-connected.927b0863447998be6c914cd07edfd639ef57cfba4b86c2faf5cf1141f9f40925.dd802eb3.png","alt":"Successful Splunk connector configuration","withLightbox":true},"children":[]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For MSP channel workspaces, Coro adds the connector to the channel workspace and, if ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Apply to all customers"]}," is enabled, to all connected descendant workspaces."]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro sends event data and metadata to the configured SIEM in real time. If the SIEM is unavailable, Coro cannot collect or send event data."]}]},"headings":[{"value":"Integrating Coro with Splunk","id":"integrating-coro-with-splunk","depth":1},{"value":"Configuring a Splunk connector","id":"configuring-a-splunk-connector","depth":2}],"frontmatter":{"seo":{"title":"Integrating Coro with Splunk"}},"lastModified":"2026-09-01T12:03:15.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/admin/siem-splunk","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}