Splunk is a data platform widely used for log aggregation, search, and analysis across IT and security data. In security operations, it’s commonly deployed as a SIEM, ingesting logs from across an environment to enable correlation, alerting, and investigation of potential threats.
How it works
Direct API integration (SIEM plugin) — Expel operates as a managed layer on top of existing Splunk alerts and searches.
Data ingested
Splunk alerts, saved searches, notable events
