Security ● Sealed v1.0 (treated)

Splunk Endpoint

Splunk Endpoint Discovery - extracts infrastructure endpoints and forwarders from Splunk.

What it does

Queries Splunk indexes to extract endpoints: Windows servers, Linux servers, network devices, workstations, and all unique hosts seen in logs. Discovers Splunk Universal Forwarders with version, type, and connectivity info. Uses Splunk search API to run SPL queries and aggregate discovered endpoints.

How the app exposes it

The module feeds into the ACQI app's dedicated results view. From there, conflicts, dependencies, and readiness scores roll up into the deal workspace.

Route in app:
/discovered/splunk-endpoint

Outputs

Each module produces a CSV with readiness and risk scores, evidence-source counts, and last-seen timestamps. The exact columns vary by module — the app's results view shows the live schema.