Skip to main content

Send Event

Sends an event in Splunk.

This node is also exposed as an AI Agent tool.

This node has 1 input port and 1 output port.

Common Properties

Every node shares these.

  • Name — the node's display name on the canvas.
  • Color — the node's colour on the canvas.
  • Delay Before (sec) — wait this long before the node runs.
  • Delay After (sec) — wait this long after the node runs.
  • Continue On Error — carry on instead of failing the flow. Defaults to false.
info

When Continue On Error is true the error is not raised at all, so a Catch node will not see it either.

Inputs

PropertyFieldDescription
Event DatainEventEvent data to send (string or JSON object)
HEC URLinHECURLSplunk HEC endpoint URL (e.g. https://localhost:8088)

Outputs

PropertyFieldDescription
SuccessoutSuccessWhether the event was sent successfully

Options

PropertyFieldDescription
HEC TokenoptCredentialsSplunk HEC Token credentials
HostoptHostHost value for the event
IndexoptIndexTarget index for the event
Skip TLS VerificationoptSkipTLSSkip TLS certificate verification
SourceoptSourceSource value for the event
SourcetypeoptSourcetypeSourcetype value for the event
Timeout (seconds)optTimeoutMaximum time in seconds to wait

Requirements

  • A Client ID from this package's Connect node, unless you set credentials directly on this node.
  • Splunk HEC Token — HTTP Event Collector token for sending events
    • value — HEC Token (password, required). HEC token from Settings > Data Inputs > HTTP Event Collector

Store these in a Vault and reference the vault item from the node, rather than typing the secret into the property.

Connect · Disconnect · Run Search · Get Search Results · List Indexes · List Saved Searches · Run Saved Search · Get Server Info · Toolkit

See also