Capabilities
Dataflect enables no-code integration between Splunk® and any API - letting you query endpoints, enrich and correlate logs with real-time context, and create custom automations and integrations - all without writing a single line of code.

Search
Centralize Splunk® searches across any data source—bringing distributed data into Splunk® as if it were native:
​
-
Query any API endpoint directly within a standard Splunk® search.
-
No-code custom search commands.
-
Normalize API responses to the Splunk® Common Information Model via props.
-
Correlate, visualize, and alert on data returned from any API.​
Enrich

Enrich and correlate your events at search time with live data from any API:
-
Build custom scripted lookups through Dataflect’s UI.
-
Pull context from any external API to enhance logs in real time.
-
Normalize and correlate enriched fields for seamless analysis.​​
Engage

Turn insights into action with no-code alert actions—enable SOAR, IT automation, and AI-driven workflows:
-
Orchestrate fulfillment of playbooks directly from Splunk® events.
-
Invoke any API to remediate issues, update systems, or notify teams.
-
Integrate your own LLMs for AI-powered decisioning and response.























