Universal Cloud REST API data source parameters for Splunk Enterprise Security
Add a Splunk Enterprise Security data source that uses the Universal Cloud REST API connector.
When you use the Universal Cloud REST API connector, there are specific parameters that you must configure.
The following table describes the parameters that require specific values to collect Universal
Cloud REST API alerts from Splunk Enterprise Security:
Parameter | Value |
---|---|
Data source type | Splunk Enterprise Security |
Connector type | Universal Cloud REST API |
Data source identifier | The Data Source identifier can be any valid value and does not need to reference a specific server. It can also be the same value as the Data source type. If you have more than one configured Universal Cloud REST API data source, ensure that you give each one a unique name. |
For a complete list of Universal Cloud REST API connector parameters and their values, see Universal Cloud REST API connector.
For more information about adding a data source, see Adding ingestion data sources.