Splunk HEC Logs
Splunk HEC Logs Sink (splunk_hec_logs)
Delivers log events to Splunk HTTP Event Collector (HEC) using HTTP(S). This sink supports at-least-once delivery, batching, buffering, and Splunk indexer acknowledgements.
Core Sink Configuration
endpoint
Required Base URL of the Splunk instance.
- Must include scheme (http or https)
- Do not include API paths
- worker appends /services/collector internally
Example
endpoint_target
Optional Controls which Splunk HEC endpoint is used.
Option | Description |
|---|---|
event | Sends structured events (default) |
raw | Sends raw text events |
Default
Notes
- raw ignores structured metadata like host, index, sourcetype
- event is recommended for most use cases
default_token
Required The Splunk HEC authentication token.
- Used unless an event overrides it via splunk_hec_token secret
- Sent as Authorization: Splunk <token>
Batching (batch)
Controls how events are grouped before sending.
batch.max_bytes
Optional (uint) Maximum uncompressed batch size in bytes.
Default
batch.max_events
Optional (uint) Maximum number of events per batch.
batch.timeout_secs
Optional (float) Maximum time to wait before flushing a batch.
Default
Buffering (buffer)
Handles temporary storage when downstream is slow or unavailable.
buffer.type
Optional
Option | Description |
|---|---|
memory | Fast, volatile (default) |
disk | Durable, slower |
Default
buffer.max_events
Optional Maximum events stored in memory buffer.
Default
buffer.max_size
Required Maximum total buffer size in bytes.
- Disk buffers must be ≥ ~256MB
buffer.when_full
Optional
Option | Description |
|---|---|
block | Apply backpressure (default) |
drop_newest | Drop incoming events |
Compression (compression)
Controls HTTP payload compression.
Option | Description |
|---|---|
none | No compression (default) |
gzip | Gzip |
snappy | Snappy |
zlib | Zlib |
zstd | Zstandard |
Encoding (encoding)
Defines how events are serialized before sending.
encoding.codec
Required
Codec | Description |
|---|---|
json | JSON-encoded events (most common) |
text | Raw message field |
cef | Common Event Format |
csv | CSV output |
gelf | GELF format |
avro | Apache Avro |
protobuf | Protobuf |
raw_message | Message field only |
encoding.only_fields
Optional Whitelist of fields to include.
encoding.except_fields
Optional Blacklist of fields to exclude.
encoding.timestamp_format
Optional
Option | Description |
|---|---|
rfc3339 | ISO format |
unix | Seconds |
unix_ms | Milliseconds |
unix_us | Microseconds |
unix_ns | Nanoseconds |
encoding.json.pretty
Optional (bool) Pretty-print JSON output.
Default
Splunk Metadata Mapping
index
Optional (template) Target Splunk index.
- Supports dynamic per-event templates
Example
source
Optional (template) Logical source of the event (e.g., filename, service).
sourcetype
Optional (template) Splunk sourcetype.
Default
host_key
Optional Overrides which event field is used as Splunk host.
timestamp_key
Optional Overrides timestamp field.
- Set to empty string ("") to omit timestamps entirely
indexed_fields
Optional List of fields added to Splunk’s indexed metadata.
HTTP Request Behavior (request)
Controls retries, rate limiting, and concurrency.
request.concurrency
Optional
Option | Description |
|---|---|
adaptive | Dynamic concurrency (default) |
none | Single request at a time |
<number> | Fixed concurrency |
request.timeout_secs
Optional Request timeout.
Default
request.retry_attempts
Optional Maximum retry count.
request.retry_initial_backoff_secs
Optional Initial retry delay.
request.retry_max_duration_secs
Optional Maximum backoff delay.
request.retry_jitter_mode
Optional
Option | Description |
|---|---|
Full | Randomized delay (default) |
None | No jitter |
request.rate_limit_num
Optional Max requests per time window.
request.rate_limit_duration_secs
Optional Rate-limit window size.
Proxy (proxy)
Controls outbound HTTP proxy usage.
proxy.enabled
Optional
proxy.http / proxy.https
Optional Proxy endpoint URIs.
proxy.no_proxy
Optional Hosts excluded from proxying.
TLS (tls)
Controls secure transport.
tls.enabled
Optional Enables TLS.
tls.verify_certificate
Optional Enables certificate validation.
tls.verify_hostname
Optional Enables hostname verification.
tls.ca_file
Optional Custom CA bundle.
tls.crt_file / tls.key_file
Optional Client certificate and private key.