...
Div |
---|
class | confluenceTableSmall |
---|
|
Name | Default Value | Context | Description |
---|
host | localhost | Both | Splunk host. | port | 8089 | Both | Splunk port | scheme | https | Both | Scheme to use as either http or https | username | null | Both | Username for Splunk | password | null | Both | Password for Splunk | connectionTimeout | 5000 | Both | Timeout in MS when connecting to Splunk server | useSunHttpsHandler | false | Both | Use sun.net.www.protocol.https.Handler Https handler to establish the Splunk Connection. Can be useful when running in application servers to avoid app. server https handling. | sslProtocol | TLSv1.2 | Both | Camel 2.16: The SSL protocol to use. Can be any of TLSv1.2,TLSv1.1,TLSv1,SSLv3. This is only in use if scheme is https | index | null | Producer | Splunk index to write to | sourceType | null | Producer | Splunk sourcetype arguement | source | null | Producer | Splunk source arguement | tcpReceiverPort | 0 | Producer | Splunk tcp receiver port when using tcp producer endpoint. | raw | false | Producer | Camel 2.16.0 : Should the body be inserted raw (true/false). If true, the body will be transformed to a string before it's send to Splunk. | initEarliestTime | null | Consumer | Initial start offset of the first search. Required | earliestTime | null | Consumer | Earliest time of the search time window. | latestTime | null | Consumer | Latest time of the search time window. | count | 0 | Consumer | A number that indicates the maximum number of entities to return. Note this is not the same as maxMessagesPerPoll which currently is unsupported | search | null | Consumer | The Splunk query to run | savedSearch | null | Consumer | The name of the query saved in Splunk to run | streaming | false | Consumer | Camel 2.14.0 : Stream exchanges as they are received from Splunk, rather than returning all of them in one batch. This has the benefit of receiving results faster, as well as requiring less memory as exchanges aren't buffered in the component. | eventHost | null | Producer | Camel 2.17: Override the default Splunk event host field |
|
Message body
Splunk operates on data in key/value pairs. The SplunkEvent class is a placeholder for such data, and should be in the message body
for the producer. Likewise it will be returned in the body per search result for the consumer.
...