---
title: "Splunk Input"
description: "read events from a Splunk Cloud/on-premises deployment"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/analyzer/splunk/module.yaml"
icon: "simple/splunk"

---
Configures a Cloud/On-premises Splunk input from which to read events to transform into typed [TenXObjects](https://doc.log10x.com/api/js/#TenXObject "Provide structured, reflective access to log/trace events read from input(s).").

Instances of this [module](https://doc.log10x.com/engine/module/) define a connection to a hosted/on-premises
Splunk cluster from which events to retrieve, as well as the querying logic used
such as chronological direction, start values, time ranges, and page size
of each API request sent.

Splunk inputs commonly run within scheduled jobs (e.g., k8s CronJob)
to retrieve a recent sample amount of events (e.g., 200MB in the last 10min) to [transform](https://doc.log10x.com/run/transform/ "Transform log and trace events into well-defined TenXObjects") into TenXObjects as part of the [Dev app](https://doc.log10x.com/apps/dev/) app.

## Architecture

The Splunk input module uses [Apache Camel](https://camel.apache.org/){target="\_blank"} to poll the Splunk REST API:

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 16px;'>🔍 Splunk API</div><div style='font-size: 14px;'>REST Endpoint</div>"] --> B["<div style='font-size: 16px;'>🛤️ Camel Route</div><div style='font-size: 14px;'>netty-http</div>"]
    B --> C["<div style='font-size: 16px;'>⚙️ 10x Pipeline</div><div style='font-size: 14px;'>Transform</div>"]
    C --> D["<div style='font-size: 16px;'>📈 TenXSummary</div><div style='font-size: 14px;'>Time-Series</div>"]

    classDef splunk fill:#9333ea88,stroke:#7c3aed,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef camel fill:#2563eb88,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef pipeline fill:#059669,stroke:#047857,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef objects fill:#ea580c88,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8

    class A splunk
    class B camel
    class C pipeline
    class D objects
```

</div>

🔍 **Splunk API**
:   Polls Splunk's [REST API](https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsearch){target="\_blank"} at regular intervals to fetch search results

🛤️ **Camel Route**
:   Submits search jobs and retrieves results in configurable page sizes

⚙️ **10x Pipeline**
:   [Transforms](https://doc.log10x.com/run/transform/ "Transform log and trace events into well-defined TenXObjects") raw events into structured TenXObjects with [symbol](https://doc.log10x.com/compile/scan/ "Capture symbol values from source code/binary files and link to an output symbol library") enrichment

📈 **TenXSummary**
:   Outputs aggregated metrics to [time-series](https://doc.log10x.com/run/output/metric/ "Write aggregated TenXSummary instances to metric outputs (e.g., Prometheus, Datadog)") outputs

=== ":material-account-key-outline: Prerequisites"

    ??? tenx-user "Splunk User Permissions"
    
        The Splunk user account needs the following capabilities:
    
        - `search` - Execute searches
        - `rest_apps_management` - Access REST API
        - `list_inputs_edit` (optional) - For advanced input management
    
    ??? tenx-cloud "Network Requirements"
    
        - Outbound HTTPS access to Splunk management port (default: 8089)
        - For Splunk Cloud: Ensure your IP is allowlisted

=== ":material-wrench-outline: Troubleshooting"

    ??? tenx-troubleshoot "SSL Certificate Errors"
    
        **Error:** `PKIX path building failed` or `unable to find valid certification path`
    
        **Solution:** For self-signed certificates in dev/test environments:
    
        ```yaml
        splunk:
          - name: DevSplunk
            verifySSL: false
        ```
    
        For production, import the Splunk CA certificate into your Java truststore.
    
    ??? tenx-troubleshoot "Authentication Failures"
    
        **Error:** `401 Unauthorized` or `Authentication failed`
    
        **Checklist:**
    
        1. Verify username/password are correct
        2. Check user has required Splunk capabilities
        3. Ensure credentials are properly passed via environment variables
        4. Test credentials with curl:
           ```bash
           curl -k -u username:password https://splunk-host:8089/services/server/info
           ```
    
    ??? tenx-troubleshoot "No Results Returned"
    
        **Symptoms:** Pipeline starts but no events are processed
    
        **Checklist:**
    
        1. Verify the search query returns results in Splunk UI
        2. Check `totalEventsLimit` isn't set too low
        3. Ensure `enabled: true` is set (or not explicitly set to false)
        4. Review query time range matches available data
    
    ??? tenx-troubleshoot "Connection Timeouts"
    
        **Error:** `Connection timed out` or `Read timed out`
    
        **Solutions:**
    
        - Check network connectivity to Splunk host
        - Verify firewall rules allow port 8089
        - For Splunk Cloud, ensure IP allowlisting
        - Increase `totalDuration` for slow networks
    
    ??? tenx-troubleshoot "Rate Limiting"
    
        **Symptoms:** Intermittent failures, `429 Too Many Requests`
    
        **Solution:** Increase polling interval:
    
        ```yaml
        splunk:
          - name: RateLimited
            queryInterval: $=parseDuration("10s")
        ```

=== ":material-shield-lock-outline: Security"

    ??? tenx-auth "Credential Management"
    
        Never hardcode credentials in configuration files:
    
        ```yaml
        # Good - uses environment variables
        username: $=TenXEnv.get("SPLUNK_USERNAME")
        password: $=TenXEnv.get("SPLUNK_PASSWORD")
    
        # Bad - hardcoded credentials
        username: admin
        password: secret123
        ```
    
    ??? tenx-keyfiles "SSL/TLS"
    
        - Always use `protocol: https` (default)
        - Only disable `verifySSL` in development environments
        - For production with custom CAs, import certificates to Java truststore
    
    ??? tenx-config "Network Security"
    
        - Use VPN or private networking when possible
        - Restrict Splunk API access to known IP ranges
        - Consider using Splunk tokens instead of username/password where supported

## :material-wrench-outline: Config Files

To configure the Splunk input module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [splunk/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/analyzer/splunk/config.yaml "splunk/config.yaml"){target="\_blank"} (<span class="tenx-tooltip" data-tooltip="The config file below contains required fields to activate this module, marked with &#10071;">** Required Fields*</span>).  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/analyzer/splunk/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/input/analyzer/splunk/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/input/analyzer/splunk/config.yaml"
                            data-copy-win="C:\log10x\configs/run/input/analyzer/splunk/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/analyzer/splunk/config.yaml">$TENX_CONFIG/run/input/analyzer/splunk/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/input/analyzer/splunk/config.yaml">./pipelines/run/input/analyzer/splunk/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogInN0cmluZyIKICAgIH0sCiAgICAidGVueCIgOiB7CiAgICAgICJ0eXBlIiA6ICJzdHJpbmciCiAgICB9LAogICAgInNwbHVuayIgOiB7CiAgICAgICJ0eXBlIiA6ICJhcnJheSIsCiAgICAgICJpdGVtcyIgOiB7CiAgICAgICAgInR5cGUiIDogIm9iamVjdCIsCiAgICAgICAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IGZhbHNlLAogICAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAgICJuYW1lIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTG9naWNhbCBuYW1lIG9mIHRoaXMgU3BsdW5rIGlucHV0XG5cblNldHMgYSBsb2dpY2FsIG5hbWUgKGUuZy4sICdteVNwbHVuaycpIGZvciB0aGlzIGlucHV0LiBUaGUgW2lucHV0TmFtZV0oaHR0cHM6Ly9kb2MubG9nMTB4LmNvbS9hcGkvanMvI1RlblhCYXNlT2JqZWN0K2lucHV0TmFtZSkgZmllbGQgIHJldHVybnMgdGhpcyB2YWx1ZSBhdCBydW4gdGltZSB0byBhbGxvdyBmb3IgaWRlbnRpZnlpbmcgYW5kIG9wZXJhdGluZyBvbiBpbnN0YW5jZXMgb3JpZ2luYXRpbmcgZnJvbSB0aGlzIGlucHV0LiIKICAgICAgICAgIH0sCiAgICAgICAgICAiZW5hYmxlZCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAiYm9vbGVhbiIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJTZXRzIHdoZXRoZXIgdGhpcyBpbnB1dCBpcyBlbmFibGVkIChkZWZhdWx0IHRydWUpXG5cblNldHMgd2hldGhlciB0byBvcGVuIHRoZSBpbnB1dCBzdHJlYW0uIFRvIGVuYWJsZSB0aGlzIGlucHV0IG9ubHkgd2hlbiBhIFtzcGx1bmtIb3N0XShodHRwczovL2RvYy5sb2cxMHguY29tL3J1bi9pbnB1dC9hbmFseXplci9zcGx1bmsvI3NwbHVua2hvc3QpIHN0YXJ0dXAgYXJndW1lbnQgdmFsdWUgaXMgdHJ1dGh5LCB1c2U6IGBgYCB5YW1sIHNwbHVua0VuYWJsZWQ6ICQ9VGVuWEVudi5nZXQoXCJzcGx1bmtIb3N0XCIpIGBgYCBUbyBsZWFybiBtb3JlIHNlZSBbVGVuWEVudi5nZXRdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vYXBpL2pzLyNUZW5YRW52LmdldCkuIChBY2NlcHRzIGJvb2xlYW4gb3Igc3RyaW5nIHdpdGggJD0gcHJlZml4IGZvciBydW50aW1lIGV2YWx1YXRpb24pIChEZWZhdWx0OiB0cnVlKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6IHRydWUKICAgICAgICAgIH0sCiAgICAgICAgICAicHJpbnRQcm9ncmVzcyIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAiYm9vbGVhbiIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJTZXRzIHdoZXRoZXIgdGhpcyBpbnB1dCBwcmludHMgdGhyb3VnaHB1dCBzdGF0cyB0byB0aGUgY29uc29sZVxuXG5TZXRzIHdoZXRoZXIgdGhpcyBpbnB1dCBwcmludHMgdGhyb3VnaHB1dCBzdGF0cyB0byB0aGUgY29uc29sZSBmb3IgdGVzdGluZyBhbiBpbnRlZ3JhdGlvbiB0byBhIHJlbW90ZSBlbmRwb2ludC4gKEFjY2VwdHMgYm9vbGVhbiBvciBzdHJpbmcgd2l0aCAkPSBwcmVmaXggZm9yIHJ1bnRpbWUgZXZhbHVhdGlvbikgKERlZmF1bHQ6IGZhbHNlKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6IGZhbHNlCiAgICAgICAgICB9LAogICAgICAgICAgImhvc3QiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJTcGx1bmsgaG9zdCBhZGRyZXNzXG5cblNldHMgdGhlIFNwbHVuayBob3N0IGFkZHJlc3MgdG8gY29ubmVjdCB0byAoZS5nLiwgYDxkZXBsb3ltZW50LW5hbWU+LnNwbHVua2Nsb3VkLmNvbWApIgogICAgICAgICAgfSwKICAgICAgICAgICJwb3J0IiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJudW1iZXIiLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiU3BsdW5rIHNlcnZlciBwb3J0XG5cblNldHMgdGhlIFNwbHVuayBzZXJ2ZXIgcG9ydCB0byBjb25uZWN0IHRvIChlLmcuLCA4MDg5KSBUaGUgcG9ydCBpcyBub3QgbmVlZGVkIGlmIHRoZSBwcm92aWRlZCBbc3BsdW5rSG9zdF0oaHR0cHM6Ly9kb2MubG9nMTB4LmNvbS9ydW4vaW5wdXQvYW5hbHl6ZXIvc3BsdW5rLyNzcGx1bmtob3N0KSBhbHJlYWR5IGVuY2Fwc3VsYXRlcyB0aGUgcG9ydCAoQWNjZXB0cyBudW1iZXIgb3Igc3RyaW5nIHdpdGggJD0gcHJlZml4IGZvciBydW50aW1lIGV2YWx1YXRpb24pIgogICAgICAgICAgfSwKICAgICAgICAgICJwcm90b2NvbCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIkRlZmluZXMgdGhlIHByb3RvY29sIHRvIGNvbm5lY3QgdG8gU3BsdW5rXG5cblNldHMgdGhlIHByb3RvY29sIHRvIGNvbm5lY3QgdG8gU3BsdW5rIHdpdGggKGUuZy4sIGh0dHBzKS4gKERlZmF1bHQ6IGh0dHBzKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6ICJodHRwcyIKICAgICAgICAgIH0sCiAgICAgICAgICAidXNlcm5hbWUiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJTcGx1bmsgdXNlciBuYW1lXG5cblNldHMgdGhlIFNwbHVuayB1c2VyIG5hbWUgdG8gYXV0aGVudGljYXRlIHdpdGggVGhpcyB2YWx1ZSBpcyBzZXQgaW50byB0aGUgJ3VzZXJuYW1lJyBoZWFkZXIgb2YgdGhlIGAvc2VydmljZXMvc2VhcmNoL3YyL2pvYnMvYCBlbmRwb2ludCIKICAgICAgICAgIH0sCiAgICAgICAgICAicGFzc3dvcmQiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJTcGx1bmsgdXNlciBwYXNzd29yZFxuXG5TZXRzIHRoZSBTcGx1bmsgdXNlciBwYXNzd29yZCB0byBhdXRoZW50aWNhdGUgd2l0aCBUaGlzIHZhbHVlIGlzIHNldCBpbnRvIHRoZSBwYXNzd29yZCBoZWFkZXIgb2YgdGhlIGAvc2VydmljZXMvc2VhcmNoL3YyL2pvYnMvYCBlbmRwb2ludCIKICAgICAgICAgIH0sCiAgICAgICAgICAidmVyaWZ5U1NMIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJib29sZWFuIiwKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIldoZXRoZXIgdG8gdmVyaWZ5IFNTTCBjZXJ0aWZpY2F0ZXMgKGRlZmF1bHQgdHJ1ZSlcblxuU2V0cyB3aGV0aGVyIHRvIHZlcmlmeSBTU0wgY2VydGlmaWNhdGVzIHdoZW4gY29ubmVjdGluZyB0byBTcGx1bmsuIFNldCB0byBgZmFsc2VgIHRvIGFsbG93IGNvbm5lY3Rpb25zIHRvIFNwbHVuayBpbnN0YW5jZXMgd2l0aCBzZWxmLXNpZ25lZCBjZXJ0aWZpY2F0ZXMuICAqKldhcm5pbmc6KiogRGlzYWJsaW5nIFNTTCB2ZXJpZmljYXRpb24gaXMgbm90IHJlY29tbWVuZGVkIGZvciBwcm9kdWN0aW9uIGVudmlyb25tZW50cy4gIEZvciBleGFtcGxlOiBgYGAgeWFtbCBzcGx1bmtWZXJpZnlTU0w6IGZhbHNlIGBgYCAoQWNjZXB0cyBib29sZWFuIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSAoRGVmYXVsdDogdHJ1ZSkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiB0cnVlCiAgICAgICAgICB9LAogICAgICAgICAgInF1ZXJ5IiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiU2VhcmNoIHF1ZXJ5IHRvIGV4ZWN1dGVcblxuU2V0cyB0aGUgU3BsdW5rIHNlYXJjaCBxdWVyeSB0byBleGVjdXRlIGZvciB0aGlzIGpvYiAoRGVmYXVsdDogc2VhcmNoICopIiwKICAgICAgICAgICAgImRlZmF1bHQiIDogInNlYXJjaCAqIgogICAgICAgICAgfSwKICAgICAgICAgICJwYWdlU2l6ZSIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk51bWJlciBvZiBldmVudHMgdG8gcmV0cmlldmUgd2l0aCBlYWNoIHJlc3VsdCBwYWdlXG5cblNldHMgdGhlIG51bWJlciBvZiBldmVudHMgdG8gcmV0cmlldmUgd2l0aCBlYWNoIHJlc3VsdCBwYWdlLiAqKlBlcmZvcm1hbmNlOioqIEluY3JlYXNlIHRvIDEwMDAtMjAwMCBmb3IgaGlnaC12b2x1bWUgZW52aXJvbm1lbnRzIHRvIHJlZHVjZSBBUEkgcm91bmQtdHJpcHMuIChBY2NlcHRzIG51bWJlciBvciBzdHJpbmcgd2l0aCAkPSBwcmVmaXggZm9yIHJ1bnRpbWUgZXZhbHVhdGlvbikgKERlZmF1bHQ6IDUwMCkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiA1MDAKICAgICAgICAgIH0sCiAgICAgICAgICAidG90YWxCeXRlc0xpbWl0IiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJudW1iZXIiLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTWF4aW11bSB0b3RhbCBieXRlcyB0byByZWFkIGZyb20gaW5wdXQgYmVmb3JlIGNsb3NpbmdcblxuU2V0cyB0aGUgbWF4aW11bSBudW1iZXIgb2YgYnl0ZXMgYSB0YXJnZXQgcGlwZWxpbmUgaW5wdXQgd2lsbCByZWFkIGludG8gdGhlIHBpcGVsaW5lLiBUaGlzIHZhbHVlIGxpbWl0cyB0aGUgdm9sdW1lIG9mIGV2ZW50cyB0byByZWFkIGZyb20gYSBsb2NhbC9yZW1vdGUgc291cmNlIChlLmcuLCBsb2cgYW5hbHl6ZXIpLiAgKipQZXJmb3JtYW5jZToqKiBJbmNyZWFzZSBmb3IgbG9uZ2VyIGFuYWx5c2lzIHdpbmRvd3MgKGUuZy4sIDIwME1CIGZvciAxMG1pbiB3aW5kb3dzKS4gIEZvciBleGFtcGxlOiBgYGAgeWFtbCBzcGx1bmtUb3RhbEJ5dGVzTGltaXQ6ICQ9cGFyc2VCeXRlcyhcIjFHQlwiKSBgYGAgKEFjY2VwdHMgbnVtYmVyIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSIKICAgICAgICAgIH0sCiAgICAgICAgICAidG90YWxFdmVudHNMaW1pdCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk1heGltdW0gdG90YWwgZXZlbnRzIHRvIHJlYWQgZnJvbSBpbnB1dCBiZWZvcmUgY2xvc2luZ1xuXG5TZXRzIHRoZSBtYXhpbXVtIG51bWJlciBvZiBldmVudHMgYSB0YXJnZXQgcGlwZWxpbmUgaW5wdXQgd2lsbCByZWFkIGludG8gdGhlIHBpcGVsaW5lLiBUaGlzIHZhbHVlIGxpbWl0cyB0aGUgdm9sdW1lIG9mIGV2ZW50cyB0byByZWFkIGZyb20gYSBsb2NhbC9yZW1vdGUgc291cmNlIChlLmcuLCBsb2cgYW5hbHl6ZXIpLiAgKipQZXJmb3JtYW5jZToqKiBBZGp1c3QgYmFzZWQgb24gbWVtb3J5IGFuZCBwcm9jZXNzaW5nIGNhcGFjaXR5LiBFYWNoIGV2ZW50IGNvbnN1bWVzIG1lbW9yeSBkdXJpbmcgcHJvY2Vzc2luZy4gKEFjY2VwdHMgbnVtYmVyIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSAoRGVmYXVsdDogMTAwMDApIiwKICAgICAgICAgICAgImRlZmF1bHQiIDogMTAwMDAKICAgICAgICAgIH0sCiAgICAgICAgICAidG90YWxEdXJhdGlvbiIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk1heGltdW0gZHVyYXRpb24gdG8ga2VlcCBpbnB1dCBvcGVuIGJlZm9yZSBjbG9zaW5nXG5cblNldHMgdGhlIG1heGltdW0gZHVyYXRpb24gYSB0YXJnZXQgcGlwZWxpbmUgaW5wdXQgd2lsbCByZW1haW4gb3Blbi4gV2hlbiByZWFjaGVkLCB0aGUgaW5wdXQgd2lsbCBjbG9zZSBhbmQgbm8gbW9yZSBkYXRhIHdpbGwgYmUgcmVhZC4gICoqUGVyZm9ybWFuY2U6KiogTWF0Y2ggdG8geW91ciBqb2Igc2NoZWR1bGluZyBpbnRlcnZhbCAoZS5nLiwgaWYgcnVubmluZyBldmVyeSAxMG1pbiwgc2V0IHRvIDEwbWluKS4gIEZvciBleGFtcGxlOiBgYGAgeWFtbCBzcGx1bmtUb3RhbER1cmF0aW9uOiAkPXBhcnNlRHVyYXRpb24oXCIxMG1pblwiKSBgYGAgKERlZmF1bHQ6IDVtaW4pIiwKICAgICAgICAgICAgImRlZmF1bHQiIDogIjVtaW4iCiAgICAgICAgICB9LAogICAgICAgICAgInF1ZXJ5SW50ZXJ2YWwiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgIm51bWJlciIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJRdWVyeSBpbnRlcnZhbCAoaW4gbWlsbGlzZWNvbmRzKSBmb3IgY2hlY2tpbmcgbmV3IGRhdGEgZnJvbSByZW1vdGUgc291cmNlXG5cblNldHMgdGhlIGludGVydmFsIGJldHdlZW4gcXVlcmllcyB0byB0aGUgcmVtb3RlIFNwbHVuayBBUEkuIFRoaXMgY29udHJvbHMgaG93IGZyZXF1ZW50bHkgdGhlIGlucHV0IHBvbGxzIGZvciBuZXcgbG9nIGRhdGEuICAqKlBlcmZvcm1hbmNlOioqIEluY3JlYXNlIGZvciByYXRlLWxpbWl0ZWQgQVBJczsgZGVjcmVhc2UgZm9yIHJlYWwtdGltZSBuZWVkcy4gIEZvciBleGFtcGxlOiBgYGAgeWFtbCBzcGx1bmtRdWVyeUludGVydmFsOiAkPXBhcnNlRHVyYXRpb24oXCI1c1wiKSBgYGAgKEFjY2VwdHMgbnVtYmVyIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSAoRGVmYXVsdDogMjAwMCkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiAyMDAwCiAgICAgICAgICB9CiAgICAgICAgfSwKICAgICAgICAicmVxdWlyZWQiIDogWwogICAgICAgICAgImhvc3QiLAogICAgICAgICAgInF1ZXJ5IgogICAgICAgIF0KICAgICAgfQogICAgfQogIH0sCiAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IHRydWUKfQ==</template>

```yaml
# 🔟❎ 'run' Splunk input configuration

# Configure a Splunk event input
# To learn more see https://doc.log10x.com/run/input/analyzer/splunk/

# Set the 10x pipeline to 'run'
tenx: run

# =============================== Dependencies ================================

include: run/modules/input/analyzer/splunk

# =============================== Splunk Options ==============================

# Multiple Splunk inputs can be defined below

splunk:

    # ---------------------------- General Options ----------------------------

    # 'name' sets a unique logical name across all pipeline inputs
  - name: Splunk
    # Disabled by default - configure host/port to enable
    enabled: false

    # --------------------------- Connection Options --------------------------

    # 'host' and 'port' set the Splunk host address to connect to (e.g., '<deployment-name>.splunkcloud.com')
    host: null    # (❗ REQUIRED)
    port: null    # (Not mandatory if the host already encapsulates it)
    protocol: "https"

    # 'username' and 'password' used to authenticate against the Splunk deployment
    #  To learn more see https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing#Authentication_and_authorization
    username: $=TenXEnv.get("SPLUNK_USERNAME") # (❗ EnvVar REQUIRED)
    password: $=TenXEnv.get("SPLUNK_PASSWORD") # (❗ EnvVar REQUIRED)

    # ----------------------------- Query Options -----------------------------

    # 'pageSize' sets the number of events to retrieve with each result page
    #  Performance: Increase to 1000-2000 for high-volume environments
    pageSize: 500

    # 'query' sets the Splunk search query to execute for this job
    query: search *

    # --------------------------- Backpressure Options -----------------------

    # 'queryInterval' sets the interval between queries to the remote API
    #  Performance: Increase for rate-limited APIs; decrease for real-time needs
    queryInterval: $=parseDuration("2s")

    # 'totalDuration' sets the max duration to try reading from the the remote input
    #  Performance: Match to your job scheduling interval
    totalDuration: $=parseDuration("5min")

    # 'totalBytesLimit' sets the max total bytes to read from the remote input
    #  Performance: Increase for longer analysis windows (e.g., 200MB for 10min)
    totalBytesLimit: $=parseBytes("50MB")

    # 'totalEventsLimit' sets the max number of events to read the remote input
    #  Performance: Adjust based on memory capacity; each event consumes memory
    totalEventsLimit: 10000

    # --------------------------- Ancillary Options ---------------------------

    # 'printProgress' controls whether to print progress gage to the console
    #  This option helps debug and test the input
    printProgress: $=!TenXEnv.get("quiet")
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") multiple Splunk input:

|Name|Description|Category|
|---|---|---|
|[splunkName](#splunkname "logical name of this Splunk input")|Logical name of this Splunk input|General|
|[splunkEnabled](#splunkenabled "sets whether this input is enabled (default true)")|Sets whether this input is enabled (default true)|General|
|[splunkPrintProgress](#splunkprintprogress "sets whether this input prints throughput stats to the console")|Sets whether this input prints throughput stats to the console|General|
|[splunkHost](#splunkhost "Splunk host address")|Splunk host address|Authentication|
|[splunkPort](#splunkport "Splunk server port")|Splunk server port|Authentication|
|[splunkProtocol](#splunkprotocol "defines the protocol to connect to Splunk")|Defines the protocol to connect to Splunk|Authentication|
|[splunkUsername](#splunkusername "Splunk user name")|Splunk user name|Authentication|
|[splunkPassword](#splunkpassword "Splunk user password")|Splunk user password|Authentication|
|[splunkVerifySSL](#splunkverifyssl "whether to verify SSL certificates (default true)")|Whether to verify SSL certificates (default true)|Authentication|
|[splunkQuery](#splunkquery "search query to execute")|Search query to execute|Query|
|[splunkPageSize](#splunkpagesize "number of events to retrieve with each result page")|Number of events to retrieve with each result page|Query|
|[splunkTotalBytesLimit](#splunktotalbyteslimit "maximum total bytes to read from input before closing")|Maximum total bytes to read from input before closing|Backpressure|
|[splunkTotalEventsLimit](#splunktotaleventslimit "maximum total events to read from input before closing")|Maximum total events to read from input before closing|Backpressure|
|[splunkTotalDuration](#splunktotalduration "maximum duration to keep input open before closing")|Maximum duration to keep input open before closing|Backpressure|
|[splunkQueryInterval](#splunkqueryinterval "query interval (in milliseconds) for checking new data from remote source")|Query interval (in milliseconds) for checking new data from remote source|Backpressure|

### General

#### :material-menu-right-outline:**`splunkName`**

Logical name of this Splunk input.

|Type|Default|Category|
|---|---|---|
|String|""|General|

Sets a logical name (e.g., 'mySplunk') for this input.
The [inputName](https://doc.log10x.com/api/js/#TenXBaseObject+inputName "Returns the context in which the current object, template or summary was created.") field
returns this value at run time to allow for identifying and operating on instances originating from this input.


#### :material-menu-right-outline:**`splunkEnabled`**

Sets whether this input is enabled (default true).

|Type|Default|Category|
|---|---|---|
|Boolean|true|General|

Sets whether to open the input stream.
To enable this input only when a [splunkHost](https://doc.log10x.com/run/input/analyzer/splunk/#splunkhost "Splunk host address") startup argument value is truthy, use:

```yaml
splunkEnabled: $=TenXEnv.get("splunkHost")
```

To learn more see [TenXEnv.get](https://doc.log10x.com/api/js/#TenXEnv.get).


#### :material-menu-right-outline:**`splunkPrintProgress`**

Sets whether this input prints throughput stats to the console.

|Type|Default|Category|
|---|---|---|
|Boolean|false|General|

Sets whether this input prints throughput stats to the console
for testing an integration to a remote endpoint.


### Authentication

#### :material-menu-right-outline:**`splunkHost`**

Splunk host address.

|Type|Default|Category|
|---|---|---|
|String|""|Authentication|

Sets the Splunk host address to connect to (e.g., `<deployment-name>.splunkcloud.com`).


#### :material-menu-right-outline:**`splunkPort`**

Splunk server port.

|Type|Default|Category|
|---|---|---|
|Number|0|Authentication|

Sets the Splunk server port to connect to (e.g., 8089)
The port is not needed if the provided [splunkHost](https://doc.log10x.com/run/input/analyzer/splunk/#splunkhost "Splunk host address") already encapsulates the port.


#### :material-menu-right-outline:**`splunkProtocol`**

Defines the protocol to connect to Splunk.

|Type|Default|Category|
|---|---|---|
|String|https|Authentication|

Sets the protocol to connect to Splunk with (e.g., https).


#### :material-menu-right-outline:**`splunkUsername`**

Splunk user name.

|Type|Default|Category|
|---|---|---|
|String|""|Authentication|

Sets the Splunk user name to authenticate with
This value is set into the 'username' header of the `/services/search/v2/jobs/` endpoint.


#### :material-menu-right-outline:**`splunkPassword`**

Splunk user password.

|Type|Default|Category|
|---|---|---|
|String|""|Authentication|

Sets the Splunk user password to authenticate with
This value is set into the password header of the `/services/search/v2/jobs/` endpoint.


#### :material-menu-right-outline:**`splunkVerifySSL`**

Whether to verify SSL certificates (default true).

|Type|Default|Category|
|---|---|---|
|Boolean|true|Authentication|

sets whether to verify SSL certificates when connecting to Splunk.
Set to `false` to allow connections to Splunk instances with self-signed certificates.

**Warning:** Disabling SSL verification is not recommended for production environments.

For example:

```yaml
splunkVerifySSL: false
```


### Query

#### :material-menu-right-outline:**`splunkQuery`**

Search query to execute.

|Type|Required|Category|
|---|---|---|
|String|✔|Query|

Sets the Splunk search query to execute for this job.


#### :material-menu-right-outline:**`splunkPageSize`**

Number of events to retrieve with each result page.

|Type|Default|Category|
|---|---|---|
|Number|500|Query|

Sets the number of events to retrieve with each result page.

**Performance:** Increase to 1000-2000 for high-volume environments to reduce API round-trips.


### Backpressure

#### :material-menu-right-outline:**`splunkTotalBytesLimit`**

Maximum total bytes to read from input before closing.

|Type|Default|Category|
|---|---|---|
|Number|50000000|Backpressure|

sets the maximum number of bytes a target pipeline input will read into the pipeline.
This value limits the volume of events to read from a local/remote source (e.g., log analyzer).

**Performance:** Increase for longer analysis windows (e.g., 200MB for 10min windows).

For example:

```yaml
splunkTotalBytesLimit: $=parseBytes("1GB")
```


#### :material-menu-right-outline:**`splunkTotalEventsLimit`**

Maximum total events to read from input before closing.

|Type|Default|Category|
|---|---|---|
|Number|10000|Backpressure|

Sets the maximum number of events a target pipeline input will read into the pipeline.
This value limits the volume of events to read from a local/remote source (e.g., log analyzer).

**Performance:** Adjust based on memory and processing capacity. Each event consumes memory during processing.


#### :material-menu-right-outline:**`splunkTotalDuration`**

Maximum duration to keep input open before closing.

|Type|Default|Category|
|---|---|---|
|String|5min|Backpressure|

sets the maximum duration a target pipeline input will remain open.
When reached, the input will close and no more data will be read.

**Performance:** Match to your job scheduling interval (e.g., if running every 10min, set to 10min).

For example:

```yaml
splunkTotalDuration: $=parseDuration("10min")
```


#### :material-menu-right-outline:**`splunkQueryInterval`**

Query interval (in milliseconds) for checking new data from remote source.

|Type|Default|Category|
|---|---|---|
|Number|2000|Backpressure|

sets the interval between queries to the remote Splunk API.
This controls how frequently the input polls for new log data.

**Performance:** Increase for rate-limited APIs; decrease for real-time needs.

For example:

```yaml
splunkQueryInterval: $=parseDuration("5s")
```


<br/>:material-github: This module is defined in [splunk/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/analyzer/splunk/module.yaml "splunk/module.yaml"){target="\_blank"}.

