Splunk® Data Stream Processor

Use the Data Stream Processor

Acrobat logo Download manual as PDF

This documentation does not apply to the most recent version of DSP. Click here for the latest version.
Acrobat logo Download topic as PDF

Create a connection to the Splunk platform in DSP

You can use either the Write to the Splunk platform with Batching or the Write to the Splunk platform functions to send data from the Data Stream Processor (DSP) to an external Splunk Enterprise or Splunk Cloud environment. Both of these functions are connectors. Before you can use any connector, you must create a connection.

If you are editing a connection that's being used by an active pipeline, you must reactivate that pipeline after making your changes.



  1. Click the Manage Connections tab.
  2. Click Create New Connection.
  3. Choose the Splunk Enterprise connector.
  4. Click Next.
  5. Complete the following fields:
    Field Description
    Name The connection name.
    Description A description of your connection.
    Splunk URL Your HEC endpoint URLs, separated by commas. Your URLs must be formatted as https://hostname:port, https://hostname:port. Load balancing is performed if more than one endpoint is provided.
    HEC token HEC token for the Splunk Enterprise or Splunk Cloud instance.

    Any credentials that you upload is transmitted securely by HTTPS, encrypted, and securely stored in a secrets manager.

  6. Click Save.

You can now use your Splunk Enterprise connection to send data to an index in Splunk Enterprise or Splunk Cloud using the HTTP Event Collector. For detailed instructions on how to send data to Splunk Enterprise or Splunk Cloud, see About sending data to Splunk Enterprise.

Last modified on 31 August, 2020
Sending data from DSP to the Splunk platform
Formatting event data in DSP

This documentation applies to the following versions of Splunk® Data Stream Processor: 1.1.0

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters