Splunk

Pull user accounts and role assignments from Splunk Enterprise or Splunk Cloud using a bearer token.

Source connector

Source connector — pulls identity and access data from Splunk into ComplianceScout where it is scored against your compliance frameworks and violation rules.

What ComplianceScout collects

After a successful sync, the following data is available in your ComplianceScout dashboard for violation detection and reporting.

  • All Splunk user accounts with username, full name, email, and roles
  • Role definitions and capabilities assigned to each role
  • Role inheritance hierarchy
  • LDAP and SAML authentication configuration

Required credentials

These fields are collected when you add the connector in the ComplianceScout dashboard. Secrets are encrypted at rest using AES-256-GCM and are never logged.

FieldTypeRequiredNotes
Management API URLURLRequirede.g. https://splunk.acme.com:8089.
Auth tokenSecretRequiredCreate an auth token in Splunk Web → Settings → Tokens. The token user needs the list_settings capability.

How to set up this connector

Follow these steps to gather the credentials above and connect Splunk to ComplianceScout.

  1. Log in to Splunk Web as an admin and go to Settings → Tokens → New Token.

  2. Set the audience to "ComplianceScout", configure an expiry, and copy the token value.

  3. Ensure the token's associated user has the list_settings and list_storage_passwords capabilities.

  4. Find your management API URL — typically https://your-splunk-host:8089.

  5. In ComplianceScout, go to Data & Secrets → Integrations → Add Connector → Splunk, enter the API URL and token, then click Test and Save.

Ready to connect Splunk?

Start a free trial — your tenant is provisioned instantly and you can wire up this integration from the connectors page.