Thanks @richgalloway for your inputs, Does the volume of data being sent to Splunk helps in determining which method to use between HEC and UF For our use case we plan to send events which has associated information (a json ~400 bytes.) and we may not be sending more than 5000 such events/day. You also mentioned about the client to get Acks for events sent via HEC and we do plan to have that. Based on the volume and our use case do you suggest we go with HEC? Also , while building and add-on is it possible to add a query which will identify specific events as alerts and ship that with add-on which customer can install in their Splunk setup?
... View more