Skip to main content

Supported Data Types:

πŸ“˜ Logs | πŸ“ˆ Metrics | 🚦 Traces

Configuration

Splunk HEC Destination Configuration

Advanced Options

Setting Source and Source Type

By default, sources like Fluent Forward do not set Splunk source and sourcetype. You can set fallback values for all events through the Source and Source Type destination options above. To set them dynamically per-event, use a Modify Attribute Processor to set Resource.com\.splunk\.source and Resource.com\.splunk\.sourcetype β€” either to a static value or from an existing log attribute. When present, these resource attributes override the static destination values.