Skip to main content
Forge delivers normalized security_event.v1 records to the Splunk HTTP Event Collector. Export scope, content detail, replay, acknowledgement, and delivery health are configured per destination. See Security Exports for shared filtering, health, multiple-destination, and replay behavior.

Events

HEC config

Filters

Detail

Prompt, tool-input, tool-output, and raw-body inclusion can be controlled independently. The export never manufactures unavailable detail.

Connection

  1. Create an HEC token allowed to write the target index, then enter its event endpoint, token, index, source, sourcetype, and host in Forge.
  2. Select categories, minimum severity, source/product/identity filters, and the detail policy.
  3. Send the synthetic test event, verify its indexed fields and acknowledgement state in Splunk, then activate the destination.

Delivery

Forge maintains a cursor per event category and records delivered events, bytes, skipped events, batch attempts, Splunk acknowledgement IDs, and dead letters. Replays target an explicit time window and category set without rewinding the continuous-delivery cursors.