Overview

The Splunk integration monitors your SIEM platform: saved searches, alerts, dashboards, indexes, and users. LowerPlane uses read-only access via API credentials to collect compliance evidence automatically.

Prerequisites

You need Splunk Admin permissions to provide API credentials with the required access.

How to Connect

1

Gather your Splunk credentials

You will need your Splunk Base URL (e.g., https://your-instance.splunkcloud.com:8089), Username, and Password for a read-only service account.
2

Create a service account (recommended)

In Splunk, create a dedicated service account with the user role for read-only API access.
3

Connect in LowerPlane

Go to Settings > Integrations in LowerPlane, find Splunk, enter your Base URL, Username, and Password, then click Connect.

What LowerPlane Monitors

Saved Searches & Alerts

Saved search configurations, alert rules, and trigger conditions.

Dashboards

Dashboard configurations and monitoring coverage.

Indexes

Index configurations, data retention policies, and ingestion status.

Users

User accounts, roles, and access permissions.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Security monitoring and log management are in place
ISO 27001Event logging and monitoring are configured
HIPAAAudit controls and log review procedures are implemented