Getting Data In

How to configure a Splunk Forwarder to forward logs to a HEC instance?

venksel1
New Member

Hi Friends,

Has anyone used a Universal forwarder to forward logs to a HEC instance? My ask is similar to the one in the thread below

https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-6-4-0-to-HEC/td-p/364436

Any inputs on how to accomplish this will be greatly appreciated.

Have a good one and keep safe!

Rachael

 

 

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Splunk's universal forwarder does not support HEC, either for input or output.
---
If this reply helps you, Karma would be appreciated.

khourihan_splun
Splunk Employee
Splunk Employee

Heavy Forwarders can accept HEC inputs, but not send out to  HEC outputs.   They can either send to Syslog or to a Splunk Indexer endpoint using Splunk2Splunk protocol.

Universal forwarders do not TODAY have HEC input capabilities.

 

 

 

yuelu
Explorer

The latest version seems to support that:

https://docs.splunk.com/Documentation/Forwarder/8.2.1/Forwarder/Configureforwardingwithoutputs.conf

In my case, I want to forward a subset of data that I received through HEC on my splunk instance to HEC on another instance.  I am not sure what DEST_KEY to use.  TCP_ROUTING?  The document indicates that I need a httpout stanza.

[httpout]
httpEventCollectorToken = eb514d08-d2bd-4e50-a10b-f71ed9922ea0
uri = https://10.222.22.122:8088

a snippet of tranforms.conf:

[route_to_another_hec]
REGEX = 99sdfskdfskdfhsjdkfhsd
DEST_KEY = _TCP_ROUTING
FORMAT = another_hec

Thanks.

MikeS
Splunk Employee
Splunk Employee

Keep in mind httpout and HEC are different.

0 Karma

mxyy31ruth
Loves-to-Learn Lots

Hi @yuelu this use case is very interesting. Right now I also try to do a similar output for HEC. But on that manual, httpout and tcpout could not be both at same time. So for other splunk TA deployed on UFs, could they also indexed with httpout into Indexer? 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...