Skip to main content

Splunk alerts

Send kwatch incident alerts to Splunk. Use the interactive manager for installation and credential setup. This page explains the provider fields and shows a minimal configuration fragment.

Before you start, have these values ready:

  • url — HEC endpoint URL.
  • token — HEC token.

Credentials, tokens, keys, passwords, and webhook URLs must be mounted from a Kubernetes Secret. Use an exact ${file:/absolute/path} reference for every field marked Secret.

Configuration​

FieldTypeRequiredSecretValidationDefaultDescription
urlstringyesnourl—HEC endpoint URL
tokenstringyesyes——HEC token
sourcestringnono——Source name (optional)
sourcetypestringnono——Source type (optional)
indexstringnono——Index name (optional)
hoststringnono——Host name (optional)
routesjsonnonojson—Optional JSON route filters.
retry.maxAttemptsintegernonointeger—Optional maximum retry attempts.
retry.delaystringnono——Optional retry delay, for example 5s.
fallbackstringnono——Optional fallback provider name.

Minimal example​

alert:
splunk:
url: <url>
token: "${file:/config/splunk-token}"

Add routes, retry, and fallback when you need delivery filtering or recovery. See the channels overview for guidance, or the complete provider reference for the catalog-wide view.