Configure auditing using Splunk App for SOAR
The auditing service in Splunk App for SOAR allows you to pull audit logs from any number of Splunk SOAR environments. To configure the auditing service, you must ensure Splunk App for SOAR connects a Splunk SOAR environment to your Splunk Cloud Platform or Enterprise environment:
- Connect Splunk App for SOAR to Splunk SOAR.
- Add an audit input. Select Manage > Edit Audit Input.
- Enter the Audit Input Name.
- Specify the Start Date and Start Time for the audit.
- Set the Interval, in seconds. Recommended interval time is 1800 seconds (30 minutes).
- Choose an Index from the dropdown menu.
- Select Save.
- Turn on the Audit Input Status toggle. If you turn off the toggle, auditing stops.