In this article, you will learn how to integrate Splunk vendors with Real-Time Coaching. Once you set up this integration, data from the Splunk vendors will be available under the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used in your Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Supported Vendors
The Splunk integration for Real-Time Coaching currently supports the following vendors:
- Bitdefender GravityZone
- Carbon Black
- Cisco Umbrella
- Cloudflare Area 1 Email Security
- Crowdstrike Falcon Insight
- Fortigate Cloud
- Malwarebytes
- Microsoft 365 and Microsoft Defender for Cloud Apps
- Microsoft Defender for Endpoint
- Microsoft Edge for Business
- Microsoft Entra ID Protection
- Mimecast
- Okta
- Palo Alto Next-Generation Firewall (NGFW)
- SentinelOne
- Sophos
- TrendAI (formerly Trend Micro)
- Zscaler
These vendors can also be integrated directly with Real-Time Coaching by following their linked direct integration guides.
Whitelist Splunk
Before setting up any integrations in your Splunk console, ensure your Splunk IP address is whitelisted in your Real-Time Coaching console by submitting a support ticket to KnowBe4. In the support ticket, let us know that you are using Splunk Cloud or Splunk Enterprise, and include the public static IP address associated with your Splunk instance. A member of our support team will whitelist your IP address and ensure that Splunk has been successfully integrated.
Locate Your Public Static IP Address
If you are using Splunk Cloud, follow these steps to locate your public static Splunk Cloud IP address:
- Open the Command Prompt (Windows) or Terminal (MacOS or Linux) program on your device.
- Enter “nslookup” in the command line text field. A new text field will appear.
-
In the new text field, enter the domain for your Splunk Cloud instance.
Tip:The start of your Splunk Cloud domain is unique to your organization, but always ends with: ".splunkcloud.com" -
Your Splunk Cloud IP address will be shown in the search results.
- Copy or screenshot the IP address to share with KnowBe4 support.
Set Up the Integration in Real-Time Coaching
To set up the Splunk vendor integration in Real-Time Coaching, follow the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate your desired vendor's tile.
- Select Configure > Splunk Integration. An integration setup page will display.
-
Under Step 1, select Enable Splunk for [[vendor]] to generate a unique Splunk Alert Title value.
Warning:Each time Splunk is enabled, a new Splunk Alert Title value is generated, and previously generated values will no longer be connected to your Real-Time Coaching console. -
Under Step 2, copy the Splunk Alert Title value by selecting the copy icon to its right. You will need this value to set up the integration in Splunk.
- For Step 3, proceed to set up the integration in Splunk.
Set Up the Integration in Splunk
After setting up the integration in Real-Time Coaching, you'll need to create an associated vendor index alert by following the steps below:
- Log in to your Splunk admin portal.
- From the Splunk homepage, use the left sidebar to select Apps > Search & Reporting.
-
Search for the name of the vendor that you set up earlier by searching for “index = [[vendor name]]” in the Search field.
Tip:To send only specific event data from the vendor to Real-Time Coaching, see the Limiting Events Sent to Real-Time Coaching section below to create a custom index, then enter that custom index here instead. -
Verify that the vendor's index search has incoming data in the Event column and that the data is accurate.
-
Create an alert from the search results by selecting Save As near the top-right corner of the screen, then selecting Alert from the drop-down menu.
-
To configure and save the alert, see the screenshot and list below:
- Enter the Splunk Alert Title token you copied earlier.
- Set the top Alert Type selection to Scheduled.
- Set the bottom Alert Type selection to Run on Cron Schedule.
-
Select the Time Range selection to open a new window. From there, select Advanced, set the Earliest field to “-6m” and the Latest field to “-1m”, then select Apply.
- Set Cron Expression to “*/5 * * * *”.
-
Set Expires to the length of time that you want this alert to show on your Triggered Alert page in Splunk.
Tip:We recommend setting this value to 365 days. - Set Trigger alert when to Number of Results, is greater than, and “0”.
-
Select Add Actions to open a drop-down menu, then select Webhook to add the When triggered > Webhook > URL field to your configuration.
-
In the URL field, enter your KnowBe4 instance’s Webhook URL from the table below:
KnowBe4 Instance Webhook URL United States https://splunk.vendor.training.knowbe4.com/v1 European Union https://splunk.vendor.eu.knowbe4.com/v1 Canada https://splunk.vendor.ca.knowbe4.com/v1 United Kingdom https://splunk.vendor.uk.knowbe4.com/v1 Germany https://splunk.vendor.de.knowbe4.com/v1
- Select Save to save the vendor index alert.
If you are using Splunk Cloud, follow these steps to allow the Webhook URL for your KnowBe4 instance:
- Log in to your Splunk Web console.
- Navigate to Settings > Server Settings > Webhook Allow List.
- In the Name field, enter “Real-Time Coaching Webhook” or your preferred title.
-
In the Value field, enter your KnowBe4 instance’s Webhook URL from the table below:
KnowBe4 Instance Webhook URL United States https://splunk.vendor.training.knowbe4.com/v1 European Union https://splunk.vendor.eu.knowbe4.com/v1 Canada https://splunk.vendor.ca.knowbe4.com/v1 United Kingdom https://splunk.vendor.uk.knowbe4.com/v1 Germany https://splunk.vendor.de.knowbe4.com/v1 - Select Save.
Limit Events Sent to Real-Time Coaching
To send only specific events from a Splunk vendor to Real-Time Coaching, create a custom index in Splunk to filter which events are sent. For more information, see Splunk’s Create Custom Indexes Create Custom Indexes (link opens in new window) article.
Map Your Users
After you’ve finished integrating your Splunk vendor, the final step is to map your users. Some vendors map your users automatically, which will be indicated on the vendor’s Setup page.
Other vendors need to be manually mapped to your users, which will also be indicated on the vendor’s Setup page. For these vendors, map your users either through mapping rules (recommended) or through a CSV file upload. For more information about user mapping, see our Map Users in Real-Time Coaching article.
Manage System Detection Rules
Once you’ve successfully integrated the Spunk vendor, use the Detection Rules subtab to manage detection rules for the integration data. For more information, see our Detection Rules Guide. For a full list of available system detection rules for Splunk vendors, see our System Detection Rules by Vendor article.
Delete a Splunk Integration
To delete a Splunk vendor integration with Real-Time Coaching, we recommend deleting it in your Splunk console first, then in Real-Time Coaching.
Deleting the Vendor Index Alert in Splunk
To delete the associated vendor index alert from Splunk, follow the steps below:
- Log in to your Splunk admin console.
- From the Splunk homepage, select Search & Reporting from the Apps menu on the left side of the screen.
- Select the Alerts subtab.
-
Locate your Splunk Alert Title in the Title column.
Note:The Splunk Alert Title can be found in your Real-Time Coaching console on the associated vendor’s Setup page. - In the Actions column, select Edit.
- From the drop-down menu, select Delete to open a pop-up confirmation window. Select Delete again to confirm deletion.
Delet the Integration in Real-Time Coaching
To delete the Splunk vendor integration from Real-Time Coaching, follow the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Splunk vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.







