🔗
Connecting Splunk to Ayzal AI
Forward your Splunk alerts to Agentic SOC for AI-powered analysis and automated response.
● Prerequisites
- An active Ayzal AI Agentic SOC Platform account with API key
- Splunk Enterprise or Splunk Cloud with admin access
● Step 1: Get Your API Key
- Log into your Agentic SOC dashboard
- Go to Settings → API Keys
- Generate a new API key or copy an existing one
● Step 2: Configure Splunk Alert Action
- In Splunk, go to Settings → Alert Actions
- Click New Alert Action
- Configure:
Action Name: forward_to_agentic_socWebhook URL: https://api.ayzalai.com/api/integrations/splunkHeaders: x-api-key = YOUR_API_KEY
- Save the alert action
● Step 3: Assign to Alerts
- Edit any existing alert or create a new one
- Under Alert Actions, add
forward_to_agentic_soc - Save the alert
✅ Result: Alerts will now flow from Splunk → Agentic SOC → AI Analysis → Your Dashboard. Each alert is enriched with threat intelligence and MITRE ATT&CK mapping.
⚠️ Make sure your API key has active status in Ayzal AI Agentic SOC Platform Settings.