Splunk Enterprise

how do integrate Splunk with external application

AmitIP
New Member

I want to integrate our own ITSM product with Splunk enterprise, how it could be done. can you please provide documentation with steps needs to follow.
our main agenda is we have event correlation feature in our App, so we want make use of that in Splunk enterprise, whatever events are generated it Splunk needs to be correlate.

I am requesting to provide full detail documentation and information for the above.

Thank you,

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not clear if you want to correlate Splunk data in your ITSM product or ITSM data in Splunk.

There are a few ways to onboard data into Splunk.

  1. Install a universal forwarder on the server to send log files to Splunk
  2. Have the server send syslog data to Splunk via a syslog server or Splunk Connect for Syslog
  3. Use the server's API to extract data for indexing
  4. Use Splunk DB Connect to pull data from the server's SQL database.
  5. Have the application send data directly to Splunk using HTTP Event Collector (HEC).

There are REST API calls available for getting data out of Splunk.

Let us know which you are trying to do and we'll point you toward to relevant docs.

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you know about Splunk Enterprise?

What have you tried so far?

What do you want to achieve with your integration? How is it supposed to work?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...