SplunkEndpoint
Splunk Endpoint Discovery - extracts infrastructure endpoints and forwarders from Splunk.
What it does
Queries Splunk indexes to extract endpoints: Windows servers, Linux servers, network devices, workstations, and all unique hosts seen in logs. Discovers Splunk Universal Forwarders with version, type, and connectivity info. Uses Splunk search API to run SPL queries and aggregate discovered endpoints.
How the app exposes it
The module runs through the ACQI discovery orchestrator and writes its rows into a dedicated results view. From there, conflicts, dependencies, and readiness scores feed the deal-wide consolidation layer.
/discovered/splunk-endpoint Outputs
Each module emits a normalised CSV keyed by entity ID with readiness and risk scores, evidence-source counts, and last-seen timestamps. The exact column set varies by module — the app's results view shows the live schema.