These docs are for Cribl Stream 4.11 and are no longer actively maintained.
See the latest version (4.13).
Splunk
You can use the following Sources to receive data from Splunk services.
Source | Description |
---|---|
Splunk HEC | Receive data over HTTP/S using the Splunk HEC |
Splunk Search | Ingest data by executing Splunk search queries |
Splunk TCP | Receive Splunk data from Universal or Heavy Forwarders |