Hi @jcm
Are you already sending PKI Spotlight data into Splunk? This add-on applies CIM compliance to the data that is sent from PKI Spotlight. If you're already ingesting the data then simply install the app for free on your Splunk instance.
If you arent already sending the PKI Spotlight data to Splunk then this can be configured in PKI Spotlight (
From PKI Spotlight controller, go to Settings > Integrations > Splunk) to setup HEC. For more information see the Installation tab on https://splunkbase.splunk.com/app/6875
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
App's description on Splunkbase doesn't list any specific external licensing requirements so you should be able to just download the app from there and use it.