Splunk Trustar
Introduction
This guide tells you how to authenticate the Splunk TruSTAR connector in Swimlane using OAuth 2.0 Client Credentials.
You will collect your TruSTAR API credentials, confirm required endpoints, and configure the connector in Swimlane.
Prerequisites
TruSTAR Access Requirements
You must have TruSTAR permissions to:
β’ Access TruSTAR Station (account settings) to generate or retrieve API credentials
β’ Confirm your tenant/environment details for API access
Required Credentials
During setup, you will collect:
β’ API Base URL
β’ Token URL
β’ API Key (used as client_id)
β’ API Secret (used as client_secret)
URLs
API Base URL
The TruSTAR REST API is accessible at the following base URL:
Token URL
Use the following Token URL to obtain an OAuth 2.0 access token:
TruSTAR Setup
Take the following steps to generate or retrieve your TruSTAR API credentials:
1. Log in to TruSTAR Station.
2. Navigate to your account settings.
3. Generate or retrieve your API access key and API secret.
4. Copy and save the following values:
β’ API Key (used as client_id in Swimlane)
β’ API Secret (used as client_secret in Swimlane)
Connector configuration in Swimlane
- Log in to Turbine.
- From the left-hand navigation pane, click ORCHESTRATION and click Assets. Asset homepage opens.
- Click the + icon to open the Configure your Connector Asset window.
- Select Splunk TruSTAR from the Asset type list.
- Fill in the Asset Settings and Asset Input as shown:
Field | Description | Required/Optional |
|---|---|---|
url | TruSTAR API Base URL (for example: https://api.trustar.co/api/2.0) | Required |
token_url | Token URL (https://api.trustar.co/oauth/token) | Required |
client_id | The API Key from TruSTAR | Required |
client_secret | The API Secret from TruSTAR | Required |
scope | Optional, leave blank unless specified | Optional |
verify_ssl | Enable/Disable SSL Verification | Optional |
http_proxy | Optional proxy configuration | Optional |
Fields with * marks are required.
- Click Create.
Troubleshooting
If you encounter a 401 or 403 error:
β’ Verify the API Key and API Secret are correct and not revoked.
β’ Confirm you are using the correct Token URL.
β’ Confirm the base API URL is correct (https://api.trustar.co/api/2.0).
β’ Regenerate the API secret if required and update the asset in Swimlane.
You have successfully authenticated the Splunk TruSTAR Connector in Swimlane.