Getting Data In

Send PDQ Connect Audit Logs to Splunk

Kat7
Explorer

Hello, 

I would like to automatically send the audit logs from PDQ Connect into our Splunk environment.  I can manually export the PDQ logs from the web interface and upload them into Splunk, but I would like to not have to do this.

Has anyone been able to accomplish this?

Thank you

Labels (1)
0 Karma

kknairr
Contributor

@Kat7 You could write a Python script to automate the ingestion by calling PDQ Connect's API to get the required data and send it to Splunk HEC endpoint. You may use the below references to setup the integration. You may use a cron job/task scheduler to run the script at specific intervals. Hope it helps.

Ref: 

PDQ Connect API – PDQ Connect Help Center

Set up and use HTTP Event Collector in Splunk Web | Splunk Enterprise (last updated 2025-07-03T23:08...

>>

If this post addressed your question, you can:

  • Give it karma to show appreciation 👍
  • Mark it as the solution if it solved your issue ✔️
  • Add a comment if you’d like more details ✏️

Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.

>>

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Kat7 

May i know some more details pls:

- is it ok to install Splunk agent on the PDQ Connect
(i did google and found this - "PDQ Connect is a cloud-native, agent-based tool for managing remote and local devices. IT teams use it to deploy software, remediate vulnerabilities, and gain remote access — all without a VPN. It’s especially useful for hybrid and distributed workforces")

--- if its ok to install Splunk agent, then, remaining tasks are simple and easy to do. 

--- if its not ok to install Splunk agent, then, you already said, "I can manually export the PDQ logs from the web interface and upload them into Splunk"
--- without installing Splunk agent, there may be other methods like HEC(http event collector), this requires some additional steps to configured


0 Karma

Kat7
Explorer

It is a cloud based service so there's no where for me to install an agent, unfortunately.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...