Skip to main content

Splunk Authentication Token

Description​

General​

  • Documentation: https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector
  • Summary: Splunk is a company providing data analysis software. This detector focuses on detecting HTTP Event Collector tokens, which are used to send events to a Splunk instance. The token is also detected alongside the URL of the instance it belongs to when both appear together, which allows for checking of the detected tokens.

Revoke the secret​

A Splunk administrator can disable or delete the token from Settings > Data inputs > HTTP Event Collector.

Details for Splunk Authentication Token​

  • Family: token

  • Category: monitoring

  • Company: Splunk

  • High recall: False

  • Validity check available: True

  • Analyzer available: False

  • Revoker available: False

  • On-premise instances exist: True

  • Only valid secrets raise an alert: False

  • Occurrences found for one million commits: 1.7

  • Prefixed: False