---
title: How do I integrate with Splunk SIEM?
description: The Splunk integration allows the Hook Security, Inc platform to push events to your Splunk SIEM tenant.
---

[Skip to content](https://support.hooksecurity.co/how-do-i-integrate-with-splunk-siem#main-content)

English

Show submenu for translations

[Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new?hsLang=en) [Customer Portal](https://support.hooksecurity.co/tickets-view?hsLang=en)

[![Hook\_Logo (3)](https://support.hooksecurity.co/hs-fs/hubfs/Hook_Logo%20(3).png?width=150&height=113&name=Hook_Logo%20(3).png)](https://www.hooksecurity.co/welcome)

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)

Open main navigation

Close main navigation

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)
- English
  
  Show submenu for translations
- [Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new)
- [Customer Portal](https://support.hooksecurity.co/tickets-view)
- [Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

[Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.hooksecurity.co/?hsLang=en)
2. [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en)
3. [3rd Party Integrations](https://support.hooksecurity.co/getting-started?hsLang=en#3rd-party-integrations)

# How do I integrate with Splunk SIEM?

## The Splunk integration allows the Hook Security, Inc platform to push events to your Splunk SIEM tenant.

Follow the steps below to push events from Hook Security, Inc to Splunk.

1. Create an HTTP Event Collector
2. Integration Store

---

#### Create an HTTP Event Collector

First, create an HTTP Event Collector in your Splunk tenant. For instructions, see [Splunk Docs](https://docs.splunk.com/Documentation/Splunk/9.0.0/Data/UsetheHTTPEventCollector).

Leave the 'Enable indexer acknowledgement' checkbox unchecked.

---

#### Integration Store

Log into Hook Security, Inc. Navigate to **Administration \> Integration Store**.

![mceclip2.png](https://support.phishingbox.com/hc/article_attachments/8493218464660/mceclip2.png)

In the Integration Store, click the 'Setup' button located on Splunk card.

![mceclip0.png](https://support.phishingbox.com/hc/article_attachments/8492890684052/mceclip0.png)

Fill out the Splunk form. Provide your splunk domain/host and the token for the HTTP Event Collector created in step one. Set the 'Active' switch to yes to immediately activate the integration upon save.

![mceclip1.png](https://support.phishingbox.com/hc/article_attachments/8492980264212/mceclip1.png)

Click the 'Test' button to test the connection. If successful, this will log a \`test\_connection\` event.

If the test is successful, enable the types of events you'd like to log then click 'Save' to finish.

*NOTE: If the 'Active' switch is not set to yes upon save, you will have to activate the integration later to push events.*

---

#### Events

- **Access Events**: If enabled, will push \`access\`, \`access\_denied\`, and \`logout\` events to Splunk.

*NOTE: More events will be available in the future. Check Hook Security, Inc change logs for updates.*

- [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en#main-content)

    - [General](https://support.hooksecurity.co/getting-started?hsLang=en#general)
    - [General Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#general-safelisting)
    - [Microsoft Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#microsoft-safelisting)
    - [GSuite Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#gsuite-safelisting)
    - [Firewall/Spam Filter Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#firewall-spam-filter-safelisting)
    - [Creating Groups/Adding Targets](https://support.hooksecurity.co/getting-started?hsLang=en#creating-groups-adding-targets)
    - [Reporting Plug-In](https://support.hooksecurity.co/getting-started?hsLang=en#reporting-plug-in)
    - [3rd Party Integrations](https://support.hooksecurity.co/getting-started?hsLang=en#3rd-party-integrations)
    - [Platform Settings](https://support.hooksecurity.co/getting-started?hsLang=en#platform-settings)
- [Hook Academy](https://support.hooksecurity.co/hook-academy?hsLang=en#main-content)

    - [Campaign Ideas](https://support.hooksecurity.co/hook-academy?hsLang=en#campaign-ideas)
    - [Industry Specific Campaigns](https://support.hooksecurity.co/hook-academy?hsLang=en#industry-specific-campaigns)
    - [Course Reviews](https://support.hooksecurity.co/hook-academy?hsLang=en#course-reviews)
    - [Mastering Reporting](https://support.hooksecurity.co/hook-academy?hsLang=en#mastering-reporting)
    - [Becoming Compliant](https://support.hooksecurity.co/hook-academy?hsLang=en#becoming-compliant)
    - [Suggest a Hook Academy Topic](https://support.hooksecurity.co/hook-academy?hsLang=en#suggest-a-hook-academy-topic)
- [Tests/Campaigns](https://support.hooksecurity.co/tests-campaigns?hsLang=en#main-content)

    - [Reseller Only](https://support.hooksecurity.co/tests-campaigns?hsLang=en#reseller-only)
- [School](https://support.hooksecurity.co/school?hsLang=en#main-content)

    - [3rd Party Integrations](https://support.hooksecurity.co/school?hsLang=en#3rd-party-integrations)
    - [Troubleshooting](https://support.hooksecurity.co/school?hsLang=en#troubleshooting)
    - [Branding](https://support.hooksecurity.co/school?hsLang=en#branding)
    - [Course](https://support.hooksecurity.co/school?hsLang=en#course)
    - [Students](https://support.hooksecurity.co/school?hsLang=en#students)
    - [Automations](https://support.hooksecurity.co/school?hsLang=en#automations)
- [Reports](https://support.hooksecurity.co/reports?hsLang=en#main-content)

    - [Generate Reports](https://support.hooksecurity.co/reports?hsLang=en#generate-reports)
- [FAQs](https://support.hooksecurity.co/faqs?hsLang=en#main-content)

    - [Troubleshooting](https://support.hooksecurity.co/faqs?hsLang=en#troubleshooting)
    - [Campaign of the Month](https://support.hooksecurity.co/faqs?hsLang=en#campaign-of-the-month)
- [Reseller Guide](https://support.hooksecurity.co/reseller-guide?hsLang=en)
- [Hook Security Updates](https://support.hooksecurity.co/hook-security-updates?hsLang=en)
- [Onboarding Guides](https://support.hooksecurity.co/onboarding-guides?hsLang=en)
- [Managed Services](https://support.hooksecurity.co/managed-services?hsLang=en)

- [Default HubSpot Blog](https://hooksecurity-6535385.hs-sites.com/blog)

[![Newsletter\_Logo-08](https://support.hooksecurity.co/hs-fs/hubfs/Newsletter_Logo-08.png?width=250&height=59&name=Newsletter_Logo-08.png "Newsletter_Logo-08")](http://hooksecurity.co)

Proudly Headquartered in Lakeland, Floirda

<https://www.linkedin.com/company/hooksecurity>

Copyright © 2026, Hook Security Inc.