Splunk
The Splunk HEC output can be used to send records to Splunk Enterprise or Splunk Cloud Platform via the HTTP Event Collector.
EF_OUTPUT_SPLUNK_HEC_ENABLE
Specifies whether the Splunk output is enabled.
Valid Values
true,false
Default
false
EF_OUTPUT_SPLUNK_HEC_CIM_ENABLE
Specifies whether the data will be sent using the Splunk Common Information Model (CIM).
Valid Values
true,false
Default
false
EF_OUTPUT_SPLUNK_HEC_ADDRESSES
This setting specifies the Splunk servers to which the output should connect. It is a comma-separated list of Splunk nodes, including port number.
Do NOT include http:// or https:// in the provided value. TLS communications is enabled/disabled using EF_OUTPUT_SPLUNK_HEC_TLS_ENABLE.
Default
127.0.0.1:8088
EF_OUTPUT_SPLUNK_HEC_TOKEN
The HTTP Event Collector token to use when sending records to Splunk.
Default
''
EF_OUTPUT_SPLUNK_HEC_BATCH_DEADLINE
The maximum time, in milliseconds, to wait for a batch of records to fill before being sent to Splunk.
Default
2000
EF_OUTPUT_SPLUNK_HEC_BATCH_MAX_BYTES
The maximum size, in bytes, for a batch of records being sent to Splunk.
Default
8388608
EF_OUTPUT_SPLUNK_HEC_TLS_ENABLE
This setting is used to enable/disable TLS connections to Splunk.
Valid Values
true,false
Default
false
EF_OUTPUT_SPLUNK_HEC_TLS_SKIP_VERIFICATION
This setting is used to enable/disable TLS verification of the Splunk server to which the output is attempting to connect.
Valid Values
true,false
Default
false
EF_OUTPUT_SPLUNK_HEC_TLS_CA_CERT_FILEPATH
The path to the Certificate Authority (CA) certificate to use for verification of the Splunk server to which the output is attempting to connect.
Default
''
EF_OUTPUT_SPLUNK_HEC_DROP_FIELDS
This setting allows for a comma-separated list of fields that are to be removed from all records.
Valid Values
any field names related to the enabled schema, comma-separated
Example
flow.export.sysuptime,flow.export.version.ver,flow.start.sysuptime,flow.end.sysuptime,flow.seq_num
Default
''
EF_OUTPUT_SPLUNK_HEC_ALLOWED_RECORD_TYPES
This setting allows for a comma-separated list of record types that the output will send will emit. If left empty, all types will be allowed by default.
Valid Values
as_path_hop,flow_option,flow,ifa_hop,telemetry,metric,log
Default
'as_path_hop,flow_option,flow,ifa_hop,telemetry,metric,log'
Last updated
Was this helpful?
