🔗 Connecting Splunk to Ayzal AI
Forward your Splunk alerts to Agentic SOC for AI-powered analysis and automated response.
📋 Prerequisites
- An active Ayzal AI Agentic SOC Platform account with API key
- Splunk Enterprise or Splunk Cloud with admin access
Step 1: Get Your API Key
- Log into your Agentic SOC dashboard
- Go to Settings → API Keys
- Generate a new API key or copy an existing one
Step 2: Configure Splunk Alert Action
- In Splunk, go to Settings → Alert Actions
- Click New Alert Action
- Configure:
Action Name: forward_to_agentic_soc
Webhook URL: https://api.ayzalai.com/api/integrations/splunk
Headers: x-api-key = YOUR_API_KEY - Save the alert action
Step 3: Assign to Alerts
- Edit any existing alert or create a new one
- Under Alert Actions, add
forward_to_agentic_soc - Save the alert
✅ Result: Alerts will now flow from Splunk → Agentic SOC → AI Analysis → Your Dashboard. Each alert is enriched with threat intelligence and MITRE ATT&CK mapping.
⚠️ Make sure your API key has active status in Ayzal AI Agentic SOC Platform Settings.