United States

Splunk onboarding, in Splunk's own vocabulary.

Indexes, sourcetypes, universal forwarders, CIM data models and SPL: Blueprint generates the full Splunk onboarding pack, not a generic template with the product name swapped in.

What a Splunk pack contains

Source runbooks per input with index and sourcetype conventions, forwarder deployment notes, CIM mapping guidance, correlation search priorities per sector, validation steps per source, and a go-live checklist covering license volume and ingestion health.

Migrating from QRadar to Splunk

With Palo Alto Networks acquiring IBM's QRadar SaaS business in late 2024, many US QRadar estates are choosing their target platform in 2026. Blueprint treats QRadar as a migration source and generates the full pack in the target platform's terms, whether that target is Splunk, Sentinel or CrowdStrike.

Splunk Enterprise Security

Data input or sourcetype
Universal Forwarder or Heavy Forwarder
CIM (Common Information Model)
Correlation search
Notable event
Index
Splunk SOAR (formerly Phantom)
  • Prerequisites confirmed, credentials received via secure channel
  • Technology Add-on installed for the source, and sourcetype confirmed
  • Data input configured, events arriving in the target index
  • 24-hour continuous ingestion confirmed via tstats against the index
  • CIM compliance verified, the source maps to the expected data model
  • Timestamp extraction correct, no future-dated or epoch-defaulted events
  • Test event confirmed, controlled action found by SPL search within 5 minutes
  • Named source owner sign-off

Partner with us

Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in the United States.

Apply as a partner