security_event.v1 records to the Splunk HTTP Event
Collector. Export scope, content detail, replay, acknowledgement, and delivery
health are configured per destination.
See Security Exports for shared filtering,
health, multiple-destination, and replay behavior.
Events
Before you start
Use a Splunk administrator who can create an HTTP Event Collector token and an existing index for Forge events. In Splunk Web, open Settings → Data inputs → HTTP Event Collector, enable HEC if necessary, and create a dedicated token. Select the permitted index and default source/sourcetype, then copy the token into Forge’s secret field. Use the HEC ingestion URL for your deployment, not its search-head UI or management API URL. Follow Splunk’s HEC setup instructions. Splunk Cloud documents indexer acknowledgement as supported only for AWS Firehose; leave Forge’s acknowledgement option off for that deployment. For Splunk Enterprise, enable it on both the token and Forge destination when your HEC service supports it. See HEC acknowledgement support.HEC config
Filters
Detail
Prompt, tool-input, tool-output, and raw-body inclusion can be controlled
independently. The export never manufactures unavailable detail.
Connection
- Open Integrations → SIEM and exports → Splunk HEC.
- Create an HEC token allowed to write the target index, then enter its event endpoint, token, index, source, sourcetype, and host in Forge.
- Select categories, minimum severity, source/product/identity filters, and the detail policy.
- Send the synthetic test event, verify its indexed fields and acknowledgement state in Splunk, then activate the destination.