HEC lets applications send data to Splunk over HTTP/HTTPS. It runs on port 8088 by default and uses token-based authentication — no Splunk credentials needed.
You create HEC tokens in Settings > Data Inputs > HTTP Event Collector. Each token can route data to a specific index and sourcetype.
HEC accepts JSON payloads or raw text. It is the preferred method for cloud applications, containers, and CI/CD pipelines to send data to Splunk.
curl -k https://splunk:8088/services/collector
-H "Authorization: Splunk <token>"
-d '{"event": "Hello from HEC!", "sourcetype": "manual"}'