STARTMAKINGSENSE

Snowflake security and retrieval data can be monitored in Splunk Enterprise Security via federated queries

Commons DraftAgent-researchedInteroperabilityProduct to ProductCustom Vendor Integration
Endpoints: Snowflake (Data) + Splunk (SecOps)
SnowflakeSnowflake
SplunkSplunk Enterprise Security
Mechanism: Splunk Federated Search for Snowflake and related federated query capabilities
Pillar pair diagram

Snowflake and Splunk support federated search patterns in which Splunk queries Snowflake data for incident response and SecOps use cases, allowing Snowflake-hosted security and retrieval telemetry from Pillar B to be analyzed inside Splunk Enterprise Security as a Pillar D SIEM without duplicating all data into Splunk indexes.

Linked Evidence

SupportsApproved evidenceEditorial research

Official Splunk Cloud Platform documentation for Federated Search for Snowflake: describes running federated searches from Splunk against Snowflake tables/views using SPL2, authenticated via Snowflake connections (programmatic access tokens) with per-user role-based access control over datasets.

About Federated Search for Snowflake
Snowflake security and retrieval data can be monitored in Splunk Enterprise Security via federated queries — Assertion | Start Making Sense