splunk.hec.tokenAuthenticate the HTTP Event Collector destination
Splunk
HTTP Event Collector destination with the ScopeMantle normalized event schema.
WHAT IT DOES
What ScopeMantle can do with Splunk.
- Forward every ScopeMantle event into Splunk Cloud or Splunk Enterprise via HTTP Event Collector
- Receive events on the ScopeMantle normalized schema with stable field names across all source connectors
- Map events to a dedicated Splunk index and sourcetype of your choosing
- Replay historical events on demand via the ScopeMantle export API to backfill new indexes
- Use the bundled Splunk app for pre-built dashboards on third-party access posture
LEAST PRIVILEGE
What we read, and what we don't.
- Read events from your Splunk environment, delivery is one-way, ScopeMantle → Splunk
- Mutate Splunk indexes, dashboards, or configuration outside what your operator installs from the ScopeMantle Splunk app
- Buffer events indefinitely on retry, failed deliveries dead-letter to S3 with a documented replay path
SETUP
Connect in a few steps.
- 01
Create an HEC token in Splunk
From Splunk Settings → Data Inputs → HTTP Event Collector, create a new token, pick the destination index, and enable HEC if not already on.
- 02
Add the destination in ScopeMantle
In ScopeMantle, go to Settings → Event Stream → Destinations and add a Splunk destination with your HEC URL and token. Optionally pin a sourcetype.
- 03
Validate end-to-end
Trigger a test event from ScopeMantle's connector test page; you should see it indexed in Splunk within seconds. Configure retry and dead-letter settings to your operational preference.
- 04
Install the ScopeMantle Splunk app (optional)
The Splunk app ships with pre-built dashboards for risk distribution, top apps, and policy actions. Install from Splunkbase and point at the index you just configured.
Find the Context.ai in your org before the attacker does.
15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.
Book a demo to see the inventory on your own tenant.