Splunk
Integrate Splunk with Cloudaware to support CMDB-aware logging workflows, dashboards, and operational visibility.
info
- Audience: Cloudaware administrators, observability teams, security operations teams, and platform teams
- Outcome: Splunk is connected to Cloudaware, so teams can use Cloudaware context in logging, monitoring, and investigation workflows
Capabilities
The integration supports:
- Splunk connection validation from Cloudaware using Splunk URL and user credentials
- CMDB-aware logging and dashboard workflows that can use Cloudaware operational context
- Correlation between Splunk logs and Cloudaware asset, application, and environment context
- Operational visibility for observability and security workflows that rely on Splunk data
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Splunk URL.
- Splunk username and password with the required access for the intended workflows.
Add a Splunk Instance to Cloudaware
- In Cloudaware, go to Admin.
- Find Splunk, then click + ADD.
- Enter the following values:
- URL: The Splunk instance URL.
- Username: The Splunk username.
- Password: The Splunk password.
- Click Save.
- Confirm that the integration status indicator is green.
tip
After the integration is connected, validate the Splunk workflows or dashboards that depend on Cloudaware context.
Troubleshooting
note
Splunk workflows depend on the integration connection and the downstream dashboards or automations that use Cloudaware context.
Authentication Fails or Integration Shows Red Status
- Verify that the Splunk URL, username, and password are correct.
- Confirm that the Splunk user can sign in to Splunk directly.
- Check whether the Splunk user account is locked, expired, or requires an authentication flow that is not supported by the integration.
Splunk Workflows Do Not Show Cloudaware Context
- Confirm that the Splunk integration status indicator is green.
- Verify that the downstream dashboard, workflow, or automation is configured to use the connected Splunk integration.
- Review the Cloudaware context fields expected by the workflow and confirm that they are available on the source records.
Connection Errors Continue After Updating Credentials
- Re-enter the credentials by editing the integration in Cloudaware.
- Confirm that the Splunk endpoint is reachable from Cloudaware.
- Check whether network controls, certificates, or Splunk access policies block the connection.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name, Splunk URL, and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate Splunk credentials or change the Splunk endpoint, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Splunk.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Splunk.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated Splunk account for Cloudaware integration workflows where possible.
- Grant the Splunk account only the permissions required for the intended dashboards, searches, or automations.
- Do not reuse personal Splunk administrator credentials for the integration.
- Rotate the Splunk password according to your organization's credential management policy.
- Review which Cloudaware asset, application, and environment context is shared with Splunk workflows, because this context may expose sensitive operational details.
- Remove or disable unused Splunk credentials when the integration is retired.