DPLens delivers to Splunk two ways.
| Destination type | What it is | Conventional port |
|---|---|---|
splunk-s2s | The protocol Splunk forwarders use to talk to an indexer | 9997 |
splunk-hec | The HTTP Event Collector | 8088 |
Choose S2S when you are delivering to indexers and want an equal-peer pool, load balancing across it, and indexer acknowledgement. Choose HEC when your Splunk platform exposes a collector endpoint and a token is how you are expected to authenticate.
Splunk is a trademark of Splunk LLC. DPLens is not affiliated with or
endorsed by Splunk. The names are used here only to say what DPLens
interoperates with.
The forwarder protocol
destinations:
- type: splunk-s2s
name: splunk
params:
addresses: "idx1.example.com:9997,idx2.example.com:9997,idx3.example.com:9997"
tls: "true"
ca_file: "C:\\ProgramData\\DPLens\\ca\\splunk-ca.pem"
cache_max_bytes: "2147483648"
splunk:
index: wineventlog
sourcetype: WinEventLog
An equal-peer pool
addresses is a pool, not a failover list: traffic rotates across every member. A member that stops accepting is taken out and re-admitted once it has recovered; only when all members are down do events go to the disk cache.
That is a different shape from address plus failover_addresses, which is a strict order with one active at a time. Use one or the other — they cannot be combined.
| Setting | What it does |
|---|---|
lb_rotate_secs | How often to move to the next member |
lb_rotate_bytes | Move after this many bytes instead, if set |
lb_readmit_secs | How long a recovered member must stay healthy before rejoining |
TLS
tls is off by default, because a stock indexer receiver on 9997 accepts plaintext and defaulting TLS on would fail against an unprepared receiver. Turn it on if your indexers expect TLS:
tls: "true"
ca_file: "C:\\ProgramData\\DPLens\\ca\\splunk-ca.pem"
s2s_server_name: "idx1.example.com"
Mutual TLS uses client_cert_handle and client_key_handle, as secret handles.
Indexer acknowledgement
Off by default. Turned on, an event is only considered delivered once the indexer confirms it, with a bounded window of events in flight and re-sending on timeout.
ack: "true"
ack_window_events: "8192"
ack_timeout_ms: "60000"
ack_resend_limit: "3"
Acknowledgement changes when an event counts as delivered, and it has a real cost: throughput with acknowledgement on is lower than with it off, because the agent waits for the indexer. Turn it on where you need delivery confirmed at the indexer, size the window for your link, and measure.
A destination with acknowledgement enabled cannot use the pause collection backpressure policy.
The HTTP Event Collector
destinations:
- type: splunk-hec
name: splunk-hec
params:
address: "hec.example.com:8088"
token_handle: "secret://splunk/hec-token"
endpoint: "event"
tls: "true"
max_request_bytes: "1048576"
max_request_events: "1024"
splunk:
index: wineventlog
sourcetype: WinEventLog
The token is required and is given as a secret handle, never as a value in the file. Seal it once:
"C:\Program Files\DPLens\dplens.exe" --set-secret secret://splunk/hec-token
| Setting | What it does |
|---|---|
endpoint | event (default) sends structured events; raw sends the record as-is for Splunk to parse |
tls | On by default — HEC is HTTP, so encryption is the sensible default |
max_request_bytes / max_request_events | How much to batch into one request |
HEC also supports an address pool and acknowledgement, with the same settings as S2S.
Index, host, source and sourcetype
Both types take a splunk: block that decides how events are labelled.
splunk:
rendering: classic
index: wineventlog
host: { field: Computer }
source: WinEventLog:Security
sourcetype: WinEventLog
sources:
iis-logs:
index: web
sourcetype: iis
firewall-syslog:
index: network
sourcetype: syslog
Each of index, host, source and sourcetype is either a fixed value or { field: <name> } to take it from the event.
sources: overrides them per source, so one destination can land different data in different indexes without your configuring several destinations.
rendering chooses how Windows events are shaped — classic for the familiar flattened form, xml for the raw event XML.
Getting this right matters
Splunk content — searches, dashboards, correlation rules — keys on sourcetype and index. If they do not match what your existing content expects, the data arrives and nothing finds it. Check against what your Splunk platform already receives before you switch anything over.
Replacing an existing forwarder
- Configure DPLens alongside, delivering to the same indexers with the same index and sourcetype.
- Compare what arrives from each over a period you are comfortable with, searching on both.
- Stop the existing forwarder.
- Remove it.
DPLens does not emit a forwarder's own internal telemetry. If you have content that reads it — forwarder health dashboards, deployment-server monitoring — that content will have nothing to read once the forwarder is gone. Check for it before you decommission.
What this destination does not do
| Indexer cluster discovery | List indexers explicitly in addresses |
| Importing Splunk app or add-on configuration | Configure DPLens directly |
| Receiving from other forwarders | DPLens sends to Splunk; it is not a receiver for the forwarder protocol |
Checking it works
- Add the destination and map a pipeline to it.
- Use Send test event from a source's row menu.
- Watch it on Live stream with this destination selected.
- Search for it in Splunk, on the index and sourcetype you configured.
If the Destinations card shows a cached backlog, the agent cannot deliver: check the address, the firewall, TLS, and — for HEC — that the token is valid and the endpoint is enabled.