Skip to main content
Forge delivers normalized security_event.v1 records to the Splunk HTTP Event Collector. Export scope, content detail, replay, acknowledgement, and delivery health are configured per destination. See Security Exports for shared filtering, health, multiple-destination, and replay behavior.

Events

Before you start

Use a Splunk administrator who can create an HTTP Event Collector token and an existing index for Forge events. In Splunk Web, open Settings → Data inputs → HTTP Event Collector, enable HEC if necessary, and create a dedicated token. Select the permitted index and default source/sourcetype, then copy the token into Forge’s secret field. Use the HEC ingestion URL for your deployment, not its search-head UI or management API URL. Follow Splunk’s HEC setup instructions. Splunk Cloud documents indexer acknowledgement as supported only for AWS Firehose; leave Forge’s acknowledgement option off for that deployment. For Splunk Enterprise, enable it on both the token and Forge destination when your HEC service supports it. See HEC acknowledgement support.

HEC config

Filters

Detail

Prompt, tool-input, tool-output, and raw-body inclusion can be controlled independently. The export never manufactures unavailable detail.

Connection

  1. Open Integrations → SIEM and exports → Splunk HEC.
  2. Create an HEC token allowed to write the target index, then enter its event endpoint, token, index, source, sourcetype, and host in Forge.
  3. Select categories, minimum severity, source/product/identity filters, and the detail policy.
  4. Send the synthetic test event, verify its indexed fields and acknowledgement state in Splunk, then activate the destination.

Delivery

Forge maintains a cursor per event category and records delivered events, bytes, skipped events, batch attempts, Splunk acknowledgement IDs, and dead letters. Replays target an explicit time window and category set without rewinding the continuous-delivery cursors.

Validate delivery and troubleshoot

After the synthetic test, find that event in the intended Splunk index. With acknowledgement enabled, also confirm the returned acknowledgement completes. HTTP acceptance, completed acknowledgement, and a searchable event are separate checks. A local HEC-compatible receiver can exercise transport and retry behavior but does not prove Splunk indexing or search.