Skip to main content

Splunk, Datadog and Slack

These Library cards send Quilr data from Quilr to your security and operations tools.

Go toQuilrAI consoleSettingsIntegrationsLibrary

Set it up​

  1. On the Library tab, click Install on the card.
  2. Connection: enter an Integration name (a tenant-visible name for this installation) and the card's own fields from the table below.
  3. Data access: choose the capabilities to enable. At least one is required.
  4. Review: check the settings and confirm. The configuration is encrypted and stored for your tenant, and the card moves to Installed.

Fields and data per card​

CardCategoryConnection fieldsCapabilitiesSends
SplunkObservabilitySplunk deployment label (for example "Security Cloud"); Index label, the destination index (for example quilr_events)Send logs (primary), Alerts & notificationsGoverned activity and findings to a Splunk security index
DatadogObservabilityDatadog site, the log delivery region (US1, US5, EU1); Service label, the service receiving Quilr events (for example quilr-security)Send logs (primary), Alerts & notificationsQuilr events, and selected alerts routed to operations teams
SlackWorkflowSlack workspace label; Channel label, the destination for notifications (for example #ai-security-alerts)Alerts & notificationsFindings and operational notifications to a Slack channel

The Slack card is for Quilr notifications. It is not the same as connecting Slack as an MCP tool (Slack MCP setup) or talking to a Workflow Agent from Slack (Chat from Slack).

Check that it works​

  • The card shows INSTALLED on the Installed tab. An error badge means it needs attention; open it to see the error.
  • Confirm that events arrive in the Splunk index or the Datadog service you named, or that notifications arrive in the Slack channel.
  • To change the fields or capabilities later, click Configure on the installed card. Uninstall removes it.