Every Portal Action, Searchable in Splunk
Splunk is where a security operations center searches everything it collects, and where a compliance reviewer expects to find a record. Nexus and AI Live Insight feed it on three paths: traces, metrics and logs over OpenTelemetry, the audit and chain-of-custody record by export, and webhooks for what must be known the moment it happens. Nothing flows back.
How it connects
The operational path is OTLP, the OpenTelemetry Protocol. The platform exports traces, metrics and logs to one endpoint an administrator configures, over HTTP with protobuf or over gRPC, with an API key, bearer token or basic credentials. All three signals share that endpoint and credential, so they cannot be split across backends. A trace sampling ratio reduces volume, and a service name and environment ride along as resource attributes. Splunk is an exercised destination; any OTLP-compatible collector receives the same export.
The record path is different. Administrative actions go to a searchable audit log that exports for review outside the platform; reading it is its own entitlement, the Audit Log Reader group. The chain of custody records every action on an item with user, email address, IP address, local date and time and the event, and exports as CSV or PDF, filtered by date, event, user, email or IP. When an AI Intelligence Hub agent reads an item, that read is in the trail too, attributed to the user who asked.
The immediate path is webhooks. The platform calls an endpoint you register on media actions, metadata changes, live session events and workflow completion, subscribed per event or per category, with every delivery logged with its retries. On AI Live Insight, each detection goes out as structured event data.
What you can do together
- Search every action on an evidence item, with account, IP address and local time, beside your VPN and identity logs, from the chain-of-custody export of Nexus.
- Alert on a retention setting changed outside business hours, from the audit log.
- Put a High-severity AI Live Insight detection into the SOC's queue with camera, confidence and time, the moment the webhook lands.
- Prove to an auditor that machine reads are on the record: an AI Intelligence Hub agent reading content appears in the same trail as a person opening it.
A scenario
- Monday, 09:05The SOC's dashboard for the portal shows a spike from Sunday night: metadata changes on several hundred evidence items in twenty minutes, arriving by webhook.
- 09:10The audit log export the team loads into Splunk each night shows an administrator account changing a retention setting at 23:50. Splunk joins it to a VPN session from an address the university never assigned.
- 10:15An Audit Log Reader exports the custody trail for the touched items, filtered to the window, as CSV into the same search. It shows the same account making a metadata edit on every item, and no download.
- 11:00The account is a shared credential a former student employee still held. It is disabled in the identity provider, the retention setting is restored, and the custody export goes into the incident record as evidence of what was and was not touched.
- Same afternoonThe SOC adds a Splunk alert on portal audit events for retention changes outside business hours, and another on AI Live Insight High-severity detections from the campus cameras.
What stays where
Splunk remains the SIEM
Indexes, searches, dashboards, alerts and retention are Splunk's. The platform sends and never reads from it, and nothing flows back into the portal.
What leaves the platform
Traces, metrics and logs over OTLP; the audit log, activity logs and the custody trail by export; events by webhook. None of these paths carries the content itself. Agent prompt tracing is a separate path to Opik or Langfuse, off by default.
Processing where you deploy
The export runs from VIDIZMO's cloud, your own cloud or on premises. An air-gapped deployment exports to a collector inside its own boundary.
Reading the trail is a privilege of its own
The Audit Log Reader group separates log access from administration, and log access levels set how much of the trail each role sees.
Products and solutions
- Nexus and AI Live Insight
- Digital Evidence Management, Enterprise Video Platform and Corporate Investigations
Next step
See it on your own Splunk instance. We will show the connection made, the data moving and the output, then size it for your deployment.
Request a demonstration or write to sales@vidizmo.ai
sales@vidizmo.ai · vidizmo.ai/integrations/catalog/splunk