As the title states, I am wondering how the Splunk Add-On for Workday pulls logs into Splunk.
@aneumeyer This add on directly pull the logs from the workday tenant and retrieving user activity through workday API's. This addon automatically parse the some of important logs streams and its readily available while searching the workday data in the Splunk.
@aneumeyer - It seems to be using the API to pull the data into Splunk via Splunk Modular Inputs. You need to configure the Account (credential) and then create the inputs which will pull the data into Splunk via APIs.
I hope this helps!!! Kindly upvote if it does!!!