Use the Splunk Enterprise Security (ES) settings to modify the preset configurations and their values as per your requirements.

Before you begin

Role required: sn_si.ingestion_profile_admin

Note: Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

Procedure

  1. Navigate to All > Splunk ES Integration > Splunk ES Settings.
  2. On the form, fill the fields.
  3. Click Save.