Getting Data In

How to configure a Splunk Forwarder to forward logs to a HEC instance?

New Member

Hi Friends,

Has anyone used a Universal forwarder to forward logs to a HEC instance? My ask is similar to the one in the thread below

Any inputs on how to accomplish this will be greatly appreciated.

Have a good one and keep safe!




Labels (1)
Tags (2)
0 Karma

Splunk's universal forwarder does not support HEC, either for input or output.
If this reply helps you, Karma would be appreciated.

Splunk Employee
Splunk Employee

Heavy Forwarders can accept HEC inputs, but not send out to  HEC outputs.   They can either send to Syslog or to a Splunk Indexer endpoint using Splunk2Splunk protocol.

Universal forwarders do not TODAY have HEC input capabilities.





The latest version seems to support that:

In my case, I want to forward a subset of data that I received through HEC on my splunk instance to HEC on another instance.  I am not sure what DEST_KEY to use.  TCP_ROUTING?  The document indicates that I need a httpout stanza.

httpEventCollectorToken = eb514d08-d2bd-4e50-a10b-f71ed9922ea0
uri =

a snippet of tranforms.conf:

REGEX = 99sdfskdfskdfhsjdkfhsd
FORMAT = another_hec


Splunk Employee
Splunk Employee

Keep in mind httpout and HEC are different.

0 Karma

Loves-to-Learn Lots

Hi @yuelu this use case is very interesting. Right now I also try to do a similar output for HEC. But on that manual, httpout and tcpout could not be both at same time. So for other splunk TA deployed on UFs, could they also indexed with httpout into Indexer? 


0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Starting With Observability: OpenTelemetry Best Practices

Tech Talk Starting With Observability: OpenTelemetry Best Practices Tuesday, October 17, 2023   |  11AM PST / ...