# Ledger records in Splunk

> Every ledger record as an OCSF event to your HTTP Event Collector, with the URL and token proven by a test event.

Source: https://immiscible.fly.dev/docs/guides/splunk

Splunk's HTTP Event Collector (HEC) takes a token; there is no OAuth for it.

1. In Splunk, **Settings**, **Data inputs**, **HTTP Event Collector**, make a token. Leave indexer acknowledgement off.
2. On the Splunk card, give the HEC URL (`https://http-inputs-<stack>.splunkcloud.com` for Splunk Cloud, or your own `https://host:8088`), the token, and optionally an index. A test event is sent; nothing is saved unless Splunk answers `{"text":"Success","code":0}`.

The URL must be https and reachable from the internet: like every outbound call Immiscible makes to an address you type, it refuses private, loopback and internal addresses. Events are sent to `/services/collector/event` with `Authorization: Splunk <token>`, sourcetype `immiscible:ocsf`, batched up to 100 a request.

Sources: [HEC endpoints](https://help.splunk.com/en/data-management/collect-http-event-data/use-hec-in-splunk-enterprise/http-event-collector-rest-api-endpoints), [event format](https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/10.4/get-data-with-http-event-collector/format-events-for-http-event-collector).
