
Splunk Send
CertifiedEnterprise EditionSend events to Splunk HTTP Event Collector
Splunk Send
Send events to Splunk HTTP Event Collector
POSTs event data to a Splunk HEC endpoint using the Splunk token authentication scheme. Accepts raw event data as a string or a Kestra internal storage file URI.
type: io.kestra.plugin.ee.splunk.events.SendExamples
Send an event to Splunk HEC
id: splunk_hec_send
namespace: company.team
tasks:
- id: send
type: io.kestra.plugin.ee.splunk.events.Send
host: http-inputs.splunkcloud.com
port: "443"
token: "{{ secret('SPLUNK_HEC_TOKEN') }}"
eventData: '{"level": "INFO", "message": "Workflow completed"}'
sourcetype: myapp:events
index: main
Forward a storage file to Splunk HEC
id: splunk_hec_file
namespace: company.team
tasks:
- id: send
type: io.kestra.plugin.ee.splunk.events.Send
host: http-inputs.splunkcloud.com
token: "{{ secret('SPLUNK_HEC_TOKEN') }}"
inputFile: "{{ outputs.previous_task.uri }}"
sourcetype: myapp:batch
Properties
host *Requiredstring
Splunk host
Hostname of the Splunk endpoint (e.g. michmed.splunkcloud.com)
token *Requiredstring
HEC token
Token for HEC authentication; sent as Authorization: Splunk <token>
eventData string
Event data
Raw event payload — a string or JSON; mutually exclusive with inputFile
hostField string
Host field
Value for the Splunk host metadata field; omitted from the payload when not set
index string
Splunk index
Target Splunk index; omitted from the payload when not set
inputFile string
Input file URI
Kestra internal storage URI of a file whose content is sent as the event; mutually exclusive with eventData; the entire file is loaded into memory
options Non-dynamic
HTTP client options
Optional HTTP client configuration — timeouts, TLS, proxy, etc.
io.kestra.core.http.client.configurations.HttpConfiguration
falseIf true, allow a failed response code (response code >= 400)
List of response code allowed for this request
The authentication to use.
io.kestra.core.http.client.configurations.BasicAuthConfiguration
The password for HTTP basic authentication.
The username for HTTP basic authentication.
io.kestra.core.http.client.configurations.BearerAuthConfiguration
The token for bearer token authentication.
io.kestra.core.http.client.configurations.DigestAuthConfiguration
The password for HTTP Digest authentication.
The username for HTTP Digest authentication.
The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
durationThe time allowed to establish a connection to the server before failing.
durationThe time an idle connection can remain in the client's connection pool before being closed.
UTF-8The default charset for the request.
java.nio.charset.Charset
trueWhether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).
Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.
trueWhether redirects should be followed automatically.
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIEDThe log level for the HTTP client.
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODYThe enabled log.
The maximum content length of the response.
The proxy configuration.
io.kestra.core.http.client.configurations.ProxyConfiguration
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTDIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
durationThe time allowed for a read connection to remain idle before closing it.
durationThe maximum time allowed for reading data from the server before failing.
The SSL request options
io.kestra.core.http.client.configurations.SslOptions
Whether to disable checking of the remote SSL certificate.
Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.
The timeout configuration.
io.kestra.core.http.client.configurations.TimeoutConfiguration
The time allowed to establish a connection to the server before failing.
PT5MThe time allowed for a read connection to remain idle before closing it.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
port string
443HEC port
Port of the HEC endpoint; defaults to 443
scheme string
httpsURL scheme
URL scheme — http or https; defaults to https
source string
Source
Splunk source field; omitted from the payload when not set
sourcetype string
Source type
Splunk sourcetype; omitted from the payload when not set
Outputs
statusCode integer
HTTP status code
Status code returned by the Splunk HEC endpoint
statusMessage string
HTTP status message
Reason phrase returned by the Splunk HEC endpoint
Metrics
events.sent counter
Number of events sent to Splunk HEC