insights
2023.10
false
- Release Notes
- Getting Started
- Access and Permissions
- Interacting with Insights
- Automation Hub Integration
- Historical data export
- Logs
- Performance and Scalability
- Real-time data export
- Overview
- Preparing Splunk
- Configure real-time data export to Splunk
- Real Time Data Export Data Model

Insights
Last updated Jun 26, 2025
Configure real-time data export to Splunk
linkNote: Before you start, make sure that Real-time data export is
enabled. To do this, check the Enabling or Disabling Insights section of the
Managing Products page from the Automation
Suite guide.
- Go to the Automation Suite Administration page.
- From the tenants list, select the tenant in which you want to enable real-time data export.
- Select Services.
- Click on the three-dot icon (⁝) from the Insights tile.
- Select Configure Real-time Data Export from the drop-down list.
- Add the Splunk endpoint and the HTTP Event Colletor (HEC) token.
- Fill in the HEC token from the Preparing Splunk procedure.
- Fill in the Splunk endpoint. This has the following format:
https://{splunk endpoint}:{hec port}
. - Fill in the port information:
- If you are using Splunk Enterprise (on-premises), the port is
8088
. - If you are using Splunk Cloud trial, the port is
8088
. - If you are using Splunk Cloud, a port number is not needed. Use
443
in this case. - If you configured an HEC port number, use the configured port.