You can use the Search & Reporting app in Splunk to search data that has been collected by Splunk.
Splunk will display event records from the database that match to your search criteria.
For example, eventtype=jamf_protect_alerts | `core_table` returns a table of Jamf Protect alerts. You can use this search to ensure that Splunk has integrated with Jamf Protect successfully.
This example returns seven events, which is the number of Jamf Protect alerts reported in the last 24 hours.