Your Canary Console is capable of posting incidents from your Canaries to an instance of Splunk that you control. We've made this feature more granular, and you can now specify an HEC URL per flock.
This guide assumes your Splunk HEC is configured, if not, kindly follow our documentation here.
If you run into any hurdles, or have any questions on the setup process, feel free to reach out to our support team here.
Step 1: Login and Select Your Flock
Log in to your Console and select the Flock you'd like to configure.
Step 2: Open Flock Settings
Head over to your flock settings, using the gear icon to the top right.
Step 3: Enable Webhook
Switch the Webhook toggle from Global to On. This configures the flock to use it's own Webhook settings, rather than matching the global settings.
Step 4: Add HEC Details
Input your HEC URL, Port and HEC Token in the appropriate fields as shown below. Finally, select Add Webhook when complete.
Step 5: Save Configuration
Click on Save when complete.
Step 6: Complete Setup
You're all set! Alert data will now be sent into your Splunk instance.