Splunk Send

Splunk Send

Certified
Enterprise Edition

Send events to Splunk HTTP Event Collector

POSTs event data to a Splunk HEC endpoint using the Splunk token authentication scheme. Accepts raw event data as a string or a Kestra internal storage file URI.

yaml
type: io.kestra.plugin.ee.splunk.events.Send

Send an event to Splunk HEC

yaml
id: splunk_hec_send
namespace: company.team

tasks:
  - id: send
    type: io.kestra.plugin.ee.splunk.events.Send
    host: http-inputs.splunkcloud.com
    port: "443"
    token: "{{ secret('SPLUNK_HEC_TOKEN') }}"
    eventData: '{"level": "INFO", "message": "Workflow completed"}'
    sourcetype: myapp:events
    index: main

Forward a storage file to Splunk HEC

yaml
id: splunk_hec_file
namespace: company.team

tasks:
  - id: send
    type: io.kestra.plugin.ee.splunk.events.Send
    host: http-inputs.splunkcloud.com
    token: "{{ secret('SPLUNK_HEC_TOKEN') }}"
    inputFile: "{{ outputs.previous_task.uri }}"
    sourcetype: myapp:batch
Properties

Splunk host

Hostname of the Splunk endpoint (e.g. michmed.splunkcloud.com)

HEC token

Token for HEC authentication; sent as Authorization: Splunk <token>

Event data

Raw event payload — a string or JSON; mutually exclusive with inputFile

Host field

Value for the Splunk host metadata field; omitted from the payload when not set

Splunk index

Target Splunk index; omitted from the payload when not set

Input file URI

Kestra internal storage URI of a file whose content is sent as the event; mutually exclusive with eventData; the entire file is loaded into memory

HTTP client options

Optional HTTP client configuration — timeouts, TLS, proxy, etc.

Definitions
allowFailedbooleanstring
Defaultfalse

If true, allow a failed response code (response code >= 400)

allowedResponseCodesarray
SubTypeinteger

List of response code allowed for this request

auth

The authentication to use.

type*Requiredobject
passwordstring

The password for HTTP basic authentication.

usernamestring

The username for HTTP basic authentication.

type*Requiredobject
tokenstring

The token for bearer token authentication.

type*Requiredobject
passwordstring

The password for HTTP Digest authentication.

usernamestring

The username for HTTP Digest authentication.

basicAuthPasswordDeprecatedstring

The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.

basicAuthUserDeprecatedstring

The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.

connectTimeoutDeprecatedstring
Formatduration

The time allowed to establish a connection to the server before failing.

connectionPoolIdleTimeoutDeprecatedstring
Formatduration

The time an idle connection can remain in the client's connection pool before being closed.

defaultCharsetstring
DefaultUTF-8

The default charset for the request.

enabledTcpExtendedKeepAlivebooleanstring
Defaulttrue

Whether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).

Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.

followRedirectsbooleanstring
Defaulttrue

Whether redirects should be followed automatically.

logLevelDeprecatedstring
Possible Values
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIED

The log level for the HTTP client.

logsarray
SubTypestring
Possible Values
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODY

The enabled log.

maxContentLengthDeprecatedinteger

The maximum content length of the response.

proxy

The proxy configuration.

addressstring

The address of the proxy server.

passwordstring

The password for proxy authentication.

portintegerstring

The port of the proxy server.

typestring
DefaultDIRECT
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

usernamestring

The username for proxy authentication.

proxyAddressDeprecatedstring

The address of the proxy server.

proxyPasswordDeprecatedstring

The password for proxy authentication.

proxyPortDeprecatedinteger

The port of the proxy server.

proxyTypeDeprecatedstring
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

proxyUsernameDeprecatedstring

The username for proxy authentication.

readIdleTimeoutDeprecatedstring
Formatduration

The time allowed for a read connection to remain idle before closing it.

readTimeoutDeprecatedstring
Formatduration

The maximum time allowed for reading data from the server before failing.

ssl

The SSL request options

insecureTrustAllCertificatesbooleanstring

Whether to disable checking of the remote SSL certificate.

Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.

timeout

The timeout configuration.

connectTimeoutstring

The time allowed to establish a connection to the server before failing.

readIdleTimeoutstring
DefaultPT5M

The time allowed for a read connection to remain idle before closing it.

Reference (ref) of the pluginDefaults to apply to this task.

Default443

HEC port

Port of the HEC endpoint; defaults to 443

Defaulthttps

URL scheme

URL scheme — http or https; defaults to https

Source

Splunk source field; omitted from the payload when not set

Source type

Splunk sourcetype; omitted from the payload when not set

HTTP status code

Status code returned by the Splunk HEC endpoint

HTTP status message

Reason phrase returned by the Splunk HEC endpoint

Number of events sent to Splunk HEC