SplunkDestinationConfiguration - Amazon Data Firehose (original) (raw)
Describes the configuration of a destination in Splunk.
Contents
HECEndpoint
The HTTP Event Collector (HEC) endpoint to which Firehose sends your data.
Type: String
Length Constraints: Minimum length of 0. Maximum length of 2048.
Pattern: .*
Required: Yes
HECEndpointType
This type can be either "Raw" or "Event."
Type: String
Valid Values: Raw | Event
Required: Yes
S3Configuration
The configuration for the backup Amazon S3 location.
Type: S3DestinationConfiguration object
Required: Yes
BufferingHints
The buffering options. If no value is specified, the default values for Splunk are used.
Type: SplunkBufferingHints object
Required: No
CloudWatchLoggingOptions
The Amazon CloudWatch logging options for your Firehose stream.
Type: CloudWatchLoggingOptions object
Required: No
HECAcknowledgmentTimeoutInSeconds
The amount of time that Firehose waits to receive an acknowledgment from Splunk after it sends it data. At the end of the timeout period, Firehose either tries to send the data again or considers it an error, based on your retry settings.
Type: Integer
Valid Range: Minimum value of 180. Maximum value of 600.
Required: No
HECToken
This is a GUID that you obtain from your Splunk cluster when you create a new HEC endpoint.
Type: String
Length Constraints: Minimum length of 0. Maximum length of 2048.
Pattern: .*
Required: No
ProcessingConfiguration
The data processing configuration.
Type: ProcessingConfiguration object
Required: No
RetryOptions
The retry behavior in case Firehose is unable to deliver data to Splunk, or if it doesn't receive an acknowledgment of receipt from Splunk.
Type: SplunkRetryOptions object
Required: No
S3BackupMode
Defines how documents should be delivered to Amazon S3. When set toFailedEventsOnly, Firehose writes any data that could not be indexed to the configured Amazon S3 destination. When set to AllEvents, Firehose delivers all incoming records to Amazon S3, and also writes failed documents to Amazon S3. The default value is FailedEventsOnly.
You can update this backup mode from FailedEventsOnly toAllEvents. You can't update it from AllEvents toFailedEventsOnly.
Type: String
Valid Values: FailedEventsOnly | AllEvents
Required: No
SecretsManagerConfiguration
The configuration that defines how you access secrets for Splunk.
Type: SecretsManagerConfiguration object
Required: No
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following:
SplunkBufferingHints
SplunkDestinationDescription
Did this page help you? - Yes
Thanks for letting us know we're doing a good job!
If you've got a moment, please tell us what we did right so we can do more of it.
Did this page help you? - No
Thanks for letting us know this page needs work. We're sorry we let you down.
If you've got a moment, please tell us how we can make the documentation better.