---
title: "Setting Up Splunk Cloud"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35398013/Setting%20Up%20Splunk%20Cloud"
format: markdown
---
> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #091e42">If you set the Source as Universal DDI or Infoblox Threat Defense and the destination as Splunk Cloud, a Infoblox</span><span style="color: #242424"> Data Connector Instance</span><span style="color: #091e42"> is still required to pass the logs from Infoblox to Splunk Cloud</span>

To add Splunk Cloud as a destination in the Infoblox Portal, complete the following:

1. Log in to the Infoblox Portal, click **Integrations **> **Data Connectors**.
2. On the *Destination Configuration *tab, choose **Splunk Cloud **from the **Create** drop-down list.
3. In the *Create Splunk Cloud Destination Configuration* dialog, complete the following:
  - **Name**: Enter the name of the destination. Select a name that best describes the destination and can be distinguished from other destinations. Enter up to 256 characters.
  - **Description: **Enter the description of the destination, up to 256 characters.
  - **State**: Use the toggle switch to enable or disable the destination configuration. The **State** is disabled by default. If the destination configuration is disabled, you will not be able to select this destination when creating a traffic flow.
  - **Tags**: Click **Add** and specify the following to associate a key with the destination:
    - **KEY**: Enter a meaningful name for the key, such as a location or department.
    - **VALUE**: Enter a value for the key. For details, see *[Managing Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397076)*.
  - **Config Options**: Choose config options either to **Configure manually** or **Import configuration**. The default is **Configure manually**. If you set the Source as Universal DDI or Infoblox Threat Defense Platform and the destination as Splunk Cloud, a Infoblox<span style="color: #242424"> Data Connector Instance</span> is still required to pass the logs from Infoblox to Splunk Cloud.
    - **Configure manually**: Configure the following sections manually.
    - **Import configuration: **
      - **Splunk Cloud Configuration Import**: Click **Select file**, browse to the respective path, and then upload the *Universal Forwarder Credentials* file that you downloaded from Splunk Cloud. When the upload is successful, the following fields are auto-populated from the uploaded file. Review all the field values and click **Save & Close **to create the destination.  
To download the *Universal Forwarder Credentials* file :
        - From your Splunk Cloud Platform instance, go to **Apps** > **Universal Forwarder**.
        - Click **Download Universal Forwarder Credential**.
4. In the **CONNECTION DETAILS** section, complete the following:
  - **FQDN/IP & Port**: Enter the FQDN or the IP address of the Splunk indexer along with the port to which you want the Data Connector to send data. For **Configure manually**, user can add multiple destination servers separated by commas.
  - **Index Name**: Enter the name of the Splunk index. An index is a collection of directories and files that are located under *$SPLUNK_HOME/var/lib/splunk*. <span style="color: #000000">To view indexes, navigate to </span>**Settings**<span style="color: #000000"> > </span>**Indexes**<span style="color: #000000"> in Splunk Cloud.</span>
  - **Log Format**: Choose one of the following log format from the drop-down menu:
    - **Splunk CIM**: Choose this to send data in CIM (Splunk Common Information Model) format.
    - **Infoblox Legacy**: Choose this to send data in CSV format.   
Depending on your selection, the log messages you have chosen will be sent to Splunk Cloud in the selected format.
5. (For secure mode only) In the **Forwarder Certificate** section, complete the following:
  - **Forwarder Certificate**: Click **Select file**, browse to the respective path, and then upload the forwarder certificate for the Splunk Cloud forwarder. You need to first generate a certificate request in .PEM format. This certificate request must be signed by the third-party Certification Authority for you to get a forwarder certificate. For more information, refer to the Splunk Cloud documentation.
  - **Certificate Key Passphrase**: Enter the key passphrase for the certificate.
6. (For secure mode only) In the **CA Certificate** section, click **Select file**, browse to the respective path, and upload the CA signed certificate for the Splunk Cloud indexer.
7. Click **Save & Close** to create the destination.

If you set the Source as Universal DDI or Infoblox Threat Defense and the destination as Splunk Cloud, a Infoblox<span style="color: #242424"> Data Connector Instance</span> is required to pass the logs from Infoblox to Splunk Cloud.