Hi @jcm Are you already sending PKI Spotlight data into Splunk? This add-on applies CIM compliance to the data that is sent from PKI Spotlight. If you're already ingesting the data then simply install the app for free on your Splunk instance. If you arent already sending the PKI Spotlight data to Splunk then this can be configured in PKI Spotlight ( From PKI Spotlight controller, go to Settings > Integrations > Splunk) to setup HEC. For more information see the Installation tab on https://splunkbase.splunk.com/app/6875 🌟 Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing
... View more