Tutorial: Forward Logs to Splunk¶ Configure HEC token & URL in CANOPYIQ_SPLUNK_HEC_*. Enable Splunk sink in config.yaml. Verify events: index: canopyiq sourcetype: canopyiq:audit