The Veza Add-on for Splunk ingests events and audit log entries from the Veza authorization platform. It connects to the Veza /api/v1 export endpoints using cursor-based pagination and OAuth2 client credentials authentication. The add-on delivers two modular inputs: one for platform events and one for system audit logs. Each input maintains a persistent checkpoint of the server cursor to ensure at-least-once delivery semantics. Events are written to separate source types for downstream processing and analysis.
Categories
Security, Fraud & Compliance, SIEM
Resources
Log in to report this app listing