Integrations / Splunk
Splunk
Splunk log management and analytics platform
Basic auth
Indexes
Actions
What Telara does
Capability matrix
Before you connect
Prerequisites
A Splunk Cloud or Splunk Enterprise instance Telara can reach.
A user who can create an authentication token or whose password you will use only if the form still asks for basic auth.
Vendor setup
Get the credential
1
Open Tokens
In Splunk, go to Settings → Tokens (or Settings → Users and authentication → Tokens). Enable token auth if an admin has not already.
2
Create a token
Click New Token. Name it for Telara. Copy the token. Prefer this over pasting a human password.
3
Paste in Telara
Settings → Integrations → Splunk. Enter the Splunk management URL (often :8089 on Enterprise) plus username/password or the token fields Telara shows.
In Telara
Connect in Telara
Basic auth
In Telara, open Settings → Integrations, choose this connector, and enter the username and password (or key) Telara asks for.
Fields Telara asks for
- Username
- Password
Knowledge
What gets indexed
| Resource | Coverage |
|---|---|
| Saved search | Partial — not every record the vendor holds is synced |
Sync
Freshness & sync
| Resource | Lag | Deletions |
|---|---|---|
| Saved search | Up to 1 day | Removed records disappear on the next full sync |
Data handling
Permissions & data handling
Telara has not published a permission list for this connector yet. Treat the vendor consent screen as the source of truth until this page lists scopes.
Excluded from semantic search: Saved search.
After connect
Verify it worked
After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.
Honesty
Known limitations
The search UI host (:8000) is not the management port. Copy the URL Splunk documents for the REST API.
Splunk Cloud vs Enterprise URLs differ. A Cloud stack token will not open an Enterprise URL.

