Skip to content

Splunk ​

Splunk context enriches an existing Pulse. It does not create Pulses.

How this helps triage: matching excerpts can show up in the summary, the first checks, and What informed this on the Pulse.

Exhale uses Splunk credentials at triage time to attach search and observability excerpts.

This is not Splunk On-Call paging ingest. If Splunk On-Call incidents should become Pulses, connect Sources → Splunk On-Call.

Connect ​

  1. Sign in as a workspace admin.
  2. Open Connections → Context → Observability context → Splunk.
  3. Save the Splunk public HTTPS host and token (or user credentials required by your deployment), then Test connection.
  4. Test connection to mark the connector configured.

See Splunk's official guide: Create authentication tokens.

Missing credentials, timeouts, or vendor 403s skip this block. Triage still completes. Send-test-alert Pulses skip live collectors.

Plan ​

Business or higher.

Connector slots are shared across Context categories (markdown runbooks use a separate document cap). Tighten AI → Prompt → Context use if excerpts are noisy or too large.

API ​

Writes use the signed-in session and CSRF. Secrets are never returned on GET.

Exhale by Kolstrom Systems LLC