SIEM integration
Automate Splunk Enterprise Security SIEM with plain language
Run saved searches against Splunk, read notable events from Enterprise Security, and send VernacSecure SuperBot™ events via HTTP Event Collector.
What you can do
Splunk — REST API / Enterprise Security notable events
- Run a search and read the results
- List saved searches and notable events
- Send an event through HTTP Event Collector
Connection: bearer authentication against https://splunk.example.com:8089. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Splunk Enterprise Security”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch saved searches — Lists saved searches.
- Fetch notable events — Runs a search for recent notable events.
- Fetch indexes — Lists available indexes.
Write actions
- Send event (HEC) — Sends a VernacSecure SuperBot™ event to HTTP Event Collector.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Exabeam Security Operations · Fortinet FortiSIEM