Export Vulnerability Findings to Splunk
Send Mondoo vulnerability findings to Splunk through the HTTP Event Collector, mapped to the Splunk CIM Vulnerabilities data model.
Send Mondoo vulnerability findings to Splunk so your security team can search, alert, and build dashboards on them alongside your other security data. Mondoo delivers the findings to a Splunk HTTP Event Collector (HEC) as events that follow the Splunk Common Information Model (CIM) Vulnerabilities data model. For how exports work in general, read Continuous Data Exports.
Requirements
- A Splunk Enterprise or Splunk Cloud Platform deployment with the HTTP Event Collector turned on, reachable from the internet.
- An HEC token. Mondoo doesn't request indexer acknowledgment, so create the token with indexer acknowledgment turned off. To learn how, read Set up and use HTTP Event Collector in the Splunk documentation.
- Editor or Owner access to the Mondoo space from which you want to export findings.
Create the integration
-
In the Mondoo App, navigate to the space. In the side navigation, select Integrations, then select INSTALL. Under Data Exports, select Splunk.

-
In the Integration Name box, enter a name for the integration.
-
Under Configure Splunk connection, fill in:
- HEC Endpoint URL. The base URL of your HTTP Event Collector, including the port, for example
https://prd-p-xxxx.splunkcloud.com:8088. Mondoo sends events to the/services/collectorpath on this host. If you leave out the scheme, Mondoo useshttps://. - HEC Token. The token you created for Mondoo.
- Skip TLS verification. Turn this on only if your HEC endpoint uses a self-signed certificate.
- HEC Endpoint URL. The base URL of your HTTP Event Collector, including the port, for example
-
Optionally, under Configure Splunk destination (optional), fill in:
- Index. The Splunk index to write events to. If you leave it empty, Splunk uses the default index configured for the HEC token.
- Source and Source Type. Values to set on each event, for example
mondooandmondoo:vulnerability. If you leave them empty, Splunk applies the token's defaults.
-
Select Create Integration.
Mondoo doesn't send data as soon as you create the integration. The first export runs within about 24 hours. To send findings right away, open the integration's detail page and select RUN.
What Mondoo sends
Each export run sends one event per vulnerability finding in the space: a full snapshot, not only the changes since the last run. Events are sent in batches of 100. Each event body uses these CIM Vulnerabilities fields:
| Field | Value |
|---|---|
category | security |
cve | The vulnerability ID, such as a CVE or advisory ID |
signature | The vulnerability summary |
cvss | The CVSS score, for example 9.8 |
severity | The CVSS severity |
dest | The name of the affected asset |
dvc | Mondoo |
tag | vulnerability |
The event time is the time of the export run. Because every run sends the full set of findings, filter searches to the most recent run when you want current counts.
Manage this integration
After it's created, find your integration under Integrations in your space's side navigation. Select it to open the detail page, where you can:
- Trigger a manual export. Exports run automatically about every 24 hours. To export immediately, select RUN.
- Check the status. ACTIVE means the integration is healthy and exporting on schedule. PENDING means Mondoo hasn't attempted the first export yet. ERROR means the last export failed. The Export Details section shows when the last export succeeded and when Mondoo last attempted one.
- Review the activity log. Most Recent Activity lists each export run's messages, such as when a job started, finished, or failed and why. Filter it to errors, warnings, or info messages.
- Change the settings. Select the pencil icon to edit the integration, for example to update credentials.
- Remove the integration. Select the trash can icon and confirm. Mondoo stops future exports but does not delete data that has already been exported.