Destinations

Sending to Splunk

The forwarder protocol and the HTTP Event Collector, with index, host, source and sourcetype.

DPLens delivers to Splunk two ways.

Destination typeWhat it isConventional port
splunk-s2sThe protocol Splunk forwarders use to talk to an indexer9997
splunk-hecThe HTTP Event Collector8088

Choose S2S when you are delivering to indexers and want an equal-peer pool, load balancing across it, and indexer acknowledgement. Choose HEC when your Splunk platform exposes a collector endpoint and a token is how you are expected to authenticate.

Splunk is a trademark of Splunk LLC. DPLens is not affiliated with or

endorsed by Splunk. The names are used here only to say what DPLens

interoperates with.

The forwarder protocol

destinations:
  - type: splunk-s2s
    name: splunk
    params:
      addresses: "idx1.example.com:9997,idx2.example.com:9997,idx3.example.com:9997"
      tls: "true"
      ca_file: "C:\\ProgramData\\DPLens\\ca\\splunk-ca.pem"
      cache_max_bytes: "2147483648"
    splunk:
      index: wineventlog
      sourcetype: WinEventLog

An equal-peer pool

addresses is a pool, not a failover list: traffic rotates across every member. A member that stops accepting is taken out and re-admitted once it has recovered; only when all members are down do events go to the disk cache.

That is a different shape from address plus failover_addresses, which is a strict order with one active at a time. Use one or the other — they cannot be combined.

SettingWhat it does
lb_rotate_secsHow often to move to the next member
lb_rotate_bytesMove after this many bytes instead, if set
lb_readmit_secsHow long a recovered member must stay healthy before rejoining

TLS

tls is off by default, because a stock indexer receiver on 9997 accepts plaintext and defaulting TLS on would fail against an unprepared receiver. Turn it on if your indexers expect TLS:

      tls: "true"
      ca_file: "C:\\ProgramData\\DPLens\\ca\\splunk-ca.pem"
      s2s_server_name: "idx1.example.com"

Mutual TLS uses client_cert_handle and client_key_handle, as secret handles.

Indexer acknowledgement

Off by default. Turned on, an event is only considered delivered once the indexer confirms it, with a bounded window of events in flight and re-sending on timeout.

      ack: "true"
      ack_window_events: "8192"
      ack_timeout_ms: "60000"
      ack_resend_limit: "3"

Acknowledgement changes when an event counts as delivered, and it has a real cost: throughput with acknowledgement on is lower than with it off, because the agent waits for the indexer. Turn it on where you need delivery confirmed at the indexer, size the window for your link, and measure.

A destination with acknowledgement enabled cannot use the pause collection backpressure policy.

The HTTP Event Collector

destinations:
  - type: splunk-hec
    name: splunk-hec
    params:
      address: "hec.example.com:8088"
      token_handle: "secret://splunk/hec-token"
      endpoint: "event"
      tls: "true"
      max_request_bytes: "1048576"
      max_request_events: "1024"
    splunk:
      index: wineventlog
      sourcetype: WinEventLog

The token is required and is given as a secret handle, never as a value in the file. Seal it once:

"C:\Program Files\DPLens\dplens.exe" --set-secret secret://splunk/hec-token
SettingWhat it does
endpointevent (default) sends structured events; raw sends the record as-is for Splunk to parse
tlsOn by default — HEC is HTTP, so encryption is the sensible default
max_request_bytes / max_request_eventsHow much to batch into one request

HEC also supports an address pool and acknowledgement, with the same settings as S2S.

Index, host, source and sourcetype

Both types take a splunk: block that decides how events are labelled.

    splunk:
      rendering: classic
      index: wineventlog
      host: { field: Computer }
      source: WinEventLog:Security
      sourcetype: WinEventLog
      sources:
        iis-logs:
          index: web
          sourcetype: iis
        firewall-syslog:
          index: network
          sourcetype: syslog

Each of index, host, source and sourcetype is either a fixed value or { field: <name> } to take it from the event.

sources: overrides them per source, so one destination can land different data in different indexes without your configuring several destinations.

rendering chooses how Windows events are shaped — classic for the familiar flattened form, xml for the raw event XML.

Getting this right matters

Splunk content — searches, dashboards, correlation rules — keys on sourcetype and index. If they do not match what your existing content expects, the data arrives and nothing finds it. Check against what your Splunk platform already receives before you switch anything over.

Replacing an existing forwarder

  1. Configure DPLens alongside, delivering to the same indexers with the same index and sourcetype.
  2. Compare what arrives from each over a period you are comfortable with, searching on both.
  3. Stop the existing forwarder.
  4. Remove it.

DPLens does not emit a forwarder's own internal telemetry. If you have content that reads it — forwarder health dashboards, deployment-server monitoring — that content will have nothing to read once the forwarder is gone. Check for it before you decommission.

What this destination does not do

Indexer cluster discoveryList indexers explicitly in addresses
Importing Splunk app or add-on configurationConfigure DPLens directly
Receiving from other forwardersDPLens sends to Splunk; it is not a receiver for the forwarder protocol

Checking it works

  1. Add the destination and map a pipeline to it.
  2. Use Send test event from a source's row menu.
  3. Watch it on Live stream with this destination selected.
  4. Search for it in Splunk, on the index and sourcetype you configured.

If the Destinations card shows a cached backlog, the agent cannot deliver: check the address, the firewall, TLS, and — for HEC — that the token is valid and the endpoint is enabled.