Summary

You can view the selections made for the Splunk configuration profile.

Procedure


Step 1

Under Profile Name, a system-generated name is displayed. Edit the value in the Name field, if you want to use a different name.

Note

The name must start with a letter, a number, or an underscore ( _ ). The name can contain include letters, numbers, and special characters: period (.), hyphen (-), underscore ( _ ), and plus (+).

Step 2

To change a value from a previous Splunk server configuration, click Edit next to the attribute.

Step 3

(Optional) To cancel the creation of the Splunk profile, click Cancel.

Step 4

(Optional) To go back to the previous step, click Back.

Step 5

To save the Splunk profile, click Submit.

Step 6

If you have configured Threat Defense events to be sent to Splunk, click Deploy.

Note

When you configure Management Center events to be sent to Splunk, eventing files are generated immediately after the profile is saved. You will be able to view the events sent from Management Center in Splunk.​ Deploy is not needed for events from Management Center.