Disconnect Splunk Federated Search

Disconnect the integration of Splunk Federated Search with Cisco Security Analytics and Logging when you no longer need federated search capabilities.

You can disconnect the integration of Splunk Federated Search with Cisco Security Analytics and Logging in Security Cloud Control at any time. After you disconnect, Splunk Cloud Platform will no longer have access to the Cisco Security Analytics and Logging data, and Splunk Cloud Platform users will not be able to perform a federated search.

Procedure


Step 1

Choose Administration > Integrations > Splunk Federated Search.

Step 2

In the Splunk Federated Search tab, click Disconnect under Connection status.

Note

If Cisco Security Analytics and Logging is disconnected from Splunk Federated Search, no data will be deleted or lost; only the access is revoked. You can reconnect at any time.


The Splunk Federated Search integration is successfully disconnected. Splunk Cloud Platform no longer has access to Cisco Security Analytics and Logging data, and federated search is disabled.