> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/sonono/siem-connectors/splunk.md).

# Splunk

{% hint style="info" %}
この SIEM コネクタは現在、リクエストに応じて利用できます。 [サポートにお問い合わせください](https://www.aikido.dev/contact) ワークスペースで有効化してもらうために。
{% endhint %}

Aikido の問題を Splunk に送信して、セキュリティの検出結果を他の監視・可観測性データと並べて管理できるようにします。

これは、チームがすでに Splunk Cloud / Splunk Enterprise を SIEM として使用しており、Aikido の検出結果をインフラ、アプリケーション、監査シグナルと一元的に相関付けたい場合に便利です。

<figure><img src="https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fn9nrT6q5NtbVUc1Lnqi7%2Fimage.png?alt=media&amp;token=f5f9a31c-74b5-4a83-840c-b67fe059fd52" alt=""><figcaption></figcaption></figure>

### 要件

接続する前に、Splunk から次の情報を取得してください:

* **HEC URL** - Splunk の HTTP Event Collector (HEC) エンドポイントのベース URL。
* **HEC ポート** - Splunk HEC が待ち受けるポート。
* **HEC トークン** - 認証用に Splunk で生成するトークン（以下を参照）。
* **ユーザー名とパスワード** *（任意）* - Aikido に Splunk のインデックスを自動作成させたい場合にのみ必要です。

### Splunk の接続

{% stepper %}
{% step %}

#### Splunk HEC トークンの取得

お使いの環境が **Splunk Enterprise**の場合は、まず HEC を有効化します。次へ進んでください: **Settings > Data Inputs > HTTP Event Collector > Global Settings**で、 **All Tokens** を **Enabled**.

に設定します。

1. その後、Splunk Cloud と Splunk Enterprise の両方でトークンを作成します: **Settings > Add Data**に移動し、次に **Monitor**をクリックし、続けて **HTTP Event Collector**.
2. を入力します。 **名前** トークンの名前（例: "Aikido"）を入力します。
3. 必要に応じて、トークンのソース名、説明、インデックスを設定します。
4. クリック **次へ**で設定内容を確認し、次に **送信**.
5. 表示されたトークン値をコピーしてください。次の手順で Aikido に貼り付けます。

Splunk インスタンスの HEC URL とポートも控えておいてください。両方必要です。
{% endstep %}

{% step %}

#### SIEM を接続する

その後、Splunk Cloud と Splunk Enterprise の両方でトークンを作成します: **Settings > Integrations** を Aikido アプリで開き、新しい SIEM 統合を追加します。 **SIEM を接続する** ダイアログで **Splunk** を選択し、次を入力します:

**設定**

* **Splunk HEC URL** - Splunk の HTTP Event Collector のベース URL。
* **Splunk HEC ポート** - HEC ポート。

**オプション** *（すべて任意）*

* **安全でない接続を許可** - 安全でない接続を許可します（例: 自己署名証明書）。本番環境には推奨されません。
* **Splunk インデックス** - データの送信先インデックス。空欄のままにすると既定のインデックスが使用されます。
* **ユーザー名** - 管理者ユーザー名。Aikido にインデックスを作成させたい場合のみ必要です。
* **インデックスを作成する** - Aikido にインデックスを自動作成させたい場合はチェックしてください。既存のインデックスを使用する場合はチェックしないでください。チェックする場合、HEC トークンが Splunk ですでに特定のインデックスにスコープ設定されていないことを確認してください。そうでないと接続エラーになります。

**認証**

* **Splunk HEC トークン** - Splunk で生成したトークン。
* **パスワード** - 必要なのは **インデックスを作成する** にチェックが入っている場合のみです。

クリック **接続をテスト** して Aikido が Splunk に到達できることを確認し、その後 **変更を保存**.
{% endstep %}

{% step %}

#### 同期する問題を設定

Splunk 統合ページの **問題入力設定**で、SIEM に同期する Aikido の問題を設定します:

* **問題のステータス** - たとえば、オープンな問題のみを同期する、または解決済みや無視済みの問題も含める、など。
* **最小重大度** - 同期する最小の重大度レベル。
* **問題タイプ** - 特定の問題タイプに限定するか、すべて同期します。
* **言語** - 特定の言語に限定するか、すべて同期します。
* **同期頻度** - Aikido が一致する問題を Splunk に送信する頻度（例: 1 時間ごと）。

クリック **設定を保存**.\
\
![](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Ffr7cLDONqBltGQsd2Evl%2Fimage.png?alt=media\&token=5553ae6f-3566-409a-bbd8-54307a7d059e)
{% endstep %}
{% endstepper %}

### イベントが届いていることの確認

Splunk で、設定したインデックス（または `source=aikido` を検索します。設定した同期頻度が経過するのを待つか、Aikido でテスト問題を発生させて、Splunk に表示されることを確認してください。

### 統合の管理

Aikido の **Settings > Integrations > Splunk** から、次のことができます:

* **統合を管理** - HEC URL、ポート、オプション、またはトークンを更新します。
* **統合を削除** - Splunk との接続を解除します。これにより今後の同期は停止しますが、すでに Splunk に送信されたイベントは削除されません。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/sonono/siem-connectors/splunk.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
