Splunk HEC Metrics
Splunk HEC Metrics Sink
Overview
The Splunk HEC Metrics sink delivers metric data to Splunk using the HTTP Event Collector (HEC) metrics endpoint. It supports reliable, at-least-once delivery with optional end-to-end acknowledgements, batching, buffering, compression, and advanced request control.
This sink is stateless and designed for high-throughput metric pipelines where delivery guarantees and backpressure handling are critical.
Authentication
default_token (required)
The default Splunk HEC token used to authenticate requests.
If an individual metric event contains a token in its metadata, that token overrides this value. Otherwise, this token is applied to all outgoing requests.
This allows multi-tenant or multi-index routing scenarios while still providing a global fallback token.
Endpoint Configuration
endpoint (required)
The base URL of the Splunk HEC endpoint.
The URL must include the scheme (http or https) but must not include a path, as the sink automatically uses the correct Splunk HEC metrics API paths.
Batching
batch
Controls how metric events are grouped before transmission.
Batching improves throughput and reduces request overhead when sending high-cardinality or high-frequency metrics.
batch.max_bytes
Maximum uncompressed size of a batch before it is flushed.
The size is calculated before serialization and compression, ensuring predictable memory usage.
batch.max_events
Maximum number of metric events in a batch before it is flushed.
batch.timeout_secs
Maximum time a batch may remain open before being flushed, regardless of size.
This ensures timely delivery for low-volume metric streams.
Buffering
buffer
Controls local buffering behavior to protect against transient failures or downstream backpressure.
buffer.type
Defines where buffered events are stored.
- memory High-performance buffering. Events are lost if worker crashes or restarts.
- disk Durable buffering. Events persist across restarts and crashes but with reduced performance.
buffer.max_size
Maximum amount of memory or disk space the buffer may consume.
Disk buffers require sufficient space to accommodate internal metadata and synchronization overhead.
buffer.max_events
Maximum number of events stored in memory buffers.
Only applicable when using in-memory buffering.
buffer.when_full
Defines behavior when the buffer reaches capacity.
- block Applies backpressure upstream, preventing data loss.
- drop_newest Drops incoming events immediately, favoring availability over reliability.
Compression
compression
Controls compression applied to outgoing requests.
Compression reduces network bandwidth usage but increases CPU overhead.
Supported algorithms include gzip, snappy, zlib, and zstd. If disabled, events are sent uncompressed.
Metric Namespacing
default_namespace
Sets a default namespace for metrics that do not already define one.
If a metric already has a namespace, it is preserved and used as a prefix to the metric name. Namespaces are separated using a dot (.).
This helps maintain consistent metric hierarchies inside Splunk.
Host and Index Routing
host_key
Overrides the name of the field used to extract the hostname sent to Splunk.
If not set, the global log_schema.host_key value is used.
index
Specifies the Splunk index to which metrics are written.
If unset, Splunk’s default index is used. This field supports worker's template syntax, allowing dynamic per-event index selection.
Source Metadata
source
Defines the source field associated with metrics in Splunk.
Typically used to identify the origin of the metric stream. If unset, Splunk assigns a default value.
Supports worker template syntax for dynamic values.
sourcetype
Defines the Splunk sourcetype assigned to metrics.
If unset, Splunk defaults to httpevent. Supports worker template syntax.
Proxy Support
proxy
Configures HTTP and HTTPS proxy behavior for outbound requests.
Useful in restricted or corporate network environments.
proxy.enabled
Globally enables or disables proxy usage.
proxy.http / proxy.https
Specifies proxy endpoints for HTTP or HTTPS traffic.
Each value must be a valid URI.
proxy.no_proxy
Defines hosts or address ranges that should bypass the proxy.
Supports exact hosts, wildcard domains, IP addresses, CIDR ranges, and catch-all patterns.
Request Middleware
request
Controls concurrency, retries, rate limits, and timeouts for outbound HTTP requests.
This layer is essential for maintaining stable ingestion under load or partial Splunk outages.
Concurrency Control
request.concurrency
Defines how many requests may be in flight concurrently.
- adaptive Uses worker's Adaptive Request Concurrency (ARC) to dynamically tune concurrency based on observed latency.
- none Forces a fixed concurrency of one request at a time.
request.adaptive_concurrency
Fine-grained tuning parameters for adaptive concurrency behavior.
These settings control how aggressively concurrency scales up or down based on RTT trends and variability and should generally remain at their defaults unless advanced tuning is required.
Rate Limiting
request.rate_limit_num
Maximum number of requests allowed within the configured time window.
request.rate_limit_duration_secs
Time window used for rate limiting.
Retry Behavior
request.retry_attempts
Maximum number of retries for failed requests.
request.retry_initial_backoff_secs
Initial delay before retrying a failed request.
Subsequent retries follow a Fibonacci backoff pattern.
request.retry_max_duration_secs
Maximum delay between retry attempts.
request.retry_jitter_mode
Controls whether retry delays include randomness.
Full jitter is recommended to prevent synchronized retry storms during recovery.
Timeouts
request.timeout_secs
Maximum amount of time a request may take before being aborted.
Setting this too low can cause duplicate ingestion due to retries against slow but successful Splunk processing.
TLS Configuration
tls
Controls TLS behavior for secure connections.
tls.ca_file
Additional CA certificates used to validate Splunk’s TLS certificate.
tls.crt_file
Client certificate used to identify worker when mutual TLS is required.
tls.key_file
Private key corresponding to the client certificate.
tls.key_pass
Passphrase used to unlock an encrypted private key.
tls.server_name
Overrides the server name used for TLS Server Name Indication (SNI).
tls.verify_certificate
Enables full certificate chain validation.
Disabling this is strongly discouraged outside of controlled testing environments.
tls.verify_hostname
Enables hostname verification against the TLS certificate.
Disabling this significantly weakens transport security and should be avoided.