Where i can find some information about Splunk integration

Hi everyone, I would like to find some information about splunk integration. Mainly Im interested about differences between push and pull option for taking alert from splunk. Anybody have experience in this matter? Now we are using push (from splunk) to chronicle (on prem btw) but I cant handle how to customize onthology, where can I test alerts like in common way using integration (pull from splunk).

0 5 308