Lidar still detects and triages inside Authdog. This channel copies the same events to the HEC endpoint you already watch. Configuration belongs to one environment.
Create the channel
In the Authdog console:
- Select the project and environment.
- Open Notifications > Channels.
- Select Add Channel.
- Set Channel Name and Channel Type to Splunk.
- Set Collector URL to the HEC base URL, for example
https://http-inputs-acme.splunkcloud.com. Authdog appends/services/collector/event. - Paste the HEC Token.
- Optionally set Sourcetype (default
authdog:audit), Source, and Index. Leave Index blank to use the token's default index. - Choose the event triggers. Leave the event list empty to drain every event. Build a narrower list from the event catalog.
- Save, then send a test delivery.
The HEC token is stored as a secret. Later edits show it as redacted. Select Change only when you are replacing it.
What lands in Splunk
Deliveries use the HEC token, not the X-Authdog-Signature header used by generic webhooks. A 2xx from Splunk is success. Failures retry with exponential backoff, starting at 60 seconds, for at most five attempts. Inspect delivery records if a test does not appear.
This is log intake, not a Lidar detector. Signals stay in the console under Lidar.
Test it
- Trigger a sign-in in the same environment.
- Search the index for sourcetype
authdog:audit, or the sourcetype you set. - Confirm a failed destination shows up in delivery records, then recovers after Splunk accepts the retry.
Repeat the channel in production with a production token. Channels do not copy between environments.
Related
| Read | To learn how to |
|---|---|
| Events and webhooks | Channel fields, retries, and the event catalog |
| Datadog | The same stream, sent to Datadog |
| Marketplace | The listing for this integration |