Short answer: Drop the "Splunk → Splunk Send Event (HEC)" action anywhere in your workflow, map the inputs from upstream nodes, and publish.
Every field can be mapped from an upstream trigger, AI step, table row, or hard-coded literal.
| Field | Type | Required | Description |
|---|---|---|---|
Event Data event | json | Required | Event Data. (JSON object). e.g. "{ "message": "User logged in", "user": "john" }" |
Source source | string | Optional | Source. e.g. "my-app" |
Source Type sourcetype | string | Optional | Source Type. e.g. "_json" |
Index index | string | Optional | Index. e.g. "main" |
{"event": "{ \"message\": \"User logged in\", \"user\": \"john\" }","source": "my-app","sourcetype": "_json","index": "main"}
{"code": 0,"text": "Success"}
Use these fields in downstream nodes for routing, logging, or error handling.
Any of these apps can fire this action as part of a workflow.
Triggered by anything in the catalog. Free tier available. No credit card.