Get data into Splunk Attack Analyzer
As a user of Splunk Attack Analyzer, you can ingest data into the application using email, the Splunk Attack Analyzer API, manual submission, and the Splunk Attack Analyzer connector.
- Use email to get data into Splunk Attack Analyzer
- Use the Splunk Attack Analyzer API to get data into Splunk Attack Analyzer
- Use manual submission to get data into Splunk Attack Analyzer
- Connect Splunk Attack Analyzer with Splunk SOAR and Splunk Mission Control
By default, Splunk Attack Analyzer retains data for 180 days after which it is deleted. If you want to retain data for a longer period of time, before the data is deleted you can use the Splunk Add-on for Splunk Attack Analyzer or the Splunk Attack Analyzer APIs to store data in the Splunk platform or another SIEM tool you might be using. See the User Guide for the Splunk Add-on for Splunk Attack Analyzer and the API documentation in Splunk Attack Analyzer for more information.
Get started with Splunk Attack Analyzer | Use email to get data into Splunk Attack Analyzer |
This documentation applies to the following versions of Splunk® Attack Analyzer: Current
Feedback submitted, thanks!