← KB

🔗 Connecting Splunk to Ayzal AI

Forward your Splunk alerts to Agentic SOC for AI-powered analysis and automated response.

📋 Prerequisites

  • An active Ayzal AI Agentic SOC Platform account with API key
  • Splunk Enterprise or Splunk Cloud with admin access

Step 1: Get Your API Key

  1. Log into your Agentic SOC dashboard
  2. Go to Settings → API Keys
  3. Generate a new API key or copy an existing one

Step 2: Configure Splunk Alert Action

  1. In Splunk, go to Settings → Alert Actions
  2. Click New Alert Action
  3. Configure:
    Action Name: forward_to_agentic_soc
    Webhook URL: https://api.ayzalai.com/api/integrations/splunk
    Headers: x-api-key = YOUR_API_KEY
  4. Save the alert action

Step 3: Assign to Alerts

  1. Edit any existing alert or create a new one
  2. Under Alert Actions, add forward_to_agentic_soc
  3. Save the alert

Result: Alerts will now flow from Splunk → Agentic SOC → AI Analysis → Your Dashboard. Each alert is enriched with threat intelligence and MITRE ATT&CK mapping.

⚠️ Make sure your API key has active status in Ayzal AI Agentic SOC Platform Settings.