SIEM integration

Automate Splunk Enterprise Security SIEM with plain language

Run saved searches against Splunk, read notable events from Enterprise Security, and send VernacSecure SuperBot™ events via HTTP Event Collector.

What you can do

Splunk — REST API / Enterprise Security notable events

  • Run a search and read the results
  • List saved searches and notable events
  • Send an event through HTTP Event Collector

Connection: bearer authentication against https://splunk.example.com:8089. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Show the last 24 hours of high severity alerts in Splunk Enterprise Security”

Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.

Get started free

Read actions
  • Fetch saved searches — Lists saved searches.
  • Fetch notable events — Runs a search for recent notable events.
  • Fetch indexes — Lists available indexes.
Write actions
  • Send event (HEC) — Sends a VernacSecure SuperBot™ event to HTTP Event Collector.