Skip to main content

Splunk alerts

Use Splunk when you want kwatch incidents delivered to this channel. This page is generated from the current provider catalog and lists every field accepted by the installed release.

Credentials, tokens, keys, passwords, and webhook URLs must be mounted from a Kubernetes Secret. Use an exact ${file:/absolute/path} reference for every field marked Secret.

Configuration​

FieldTypeRequiredSecretValidationDefaultDescription
urlstringyesnourl—HEC endpoint URL
tokenstringyesyes——HEC token
sourcestringnono——Source name (optional)
sourcetypestringnono——Source type (optional)
indexstringnono——Index name (optional)
hoststringnono——Host name (optional)
routesjsonnonojson—Optional JSON route filters.
retry.maxAttemptsintegernonointeger—Optional maximum retry attempts.
retry.delaystringnono——Optional retry delay, for example 5s.
fallbackstringnono——Optional fallback provider name.

Minimal example​

alert:
splunk:
url: <url>

Add routes, retry, and fallback when you need delivery filtering or recovery. See the channels overview for guidance, or the complete provider reference for the catalog-wide view.