Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Splunk data input configuration fields

Description of the fields on the Splunk data input configuration form.

Basic configuration

FieldDescription
Data input nameName of the new data input. This field is required.
DescriptionDescription of the data input.
MID Server

The MID Server to which the logs stream.Note:

  • You can select only MID Servers that support basic authentication. MID Servers that support mTLS are not listed.
  • The default maximum number of data inputs streaming logs to a single MID Server is 10. You can modify this number in the MID Server properties.

This field is required.

PortThe port for the MID Server. Make sure that your organization’s security team opens the selected port in the MID Server. This field is required.
Transport Protocol

The protocol used for streaming log messages to your ServiceNow instance.- TCP - When using the Transmission Control Protocol (TCP) protocol, all logs will reach the instance. However, the Splunk pipeline might be blocked if the MID Server is down or the connection to it is lost. TCP is the default transport protocol. - UDP - When using the User Datagram Protocol (UDP) protocol, the Splunk pipeline will never be blocked. However, some logs might be dropped before they reach the instance.

For more information about streaming log data using the TCP or UCP transport protocol, see the Streaming Splunk data using Heavy Forwarder: Selecting TCP or UDP [KB0998928] article in the Now Support Knowledge Base.

Use Cooked Data

Option to ingest log data from Splunk in the preprocessed ("cooked") format that Splunk uses on the forwarder.Ingesting data into HLA in this format ensures that each log line retains the relevant contextual information that Splunk embeds into it.

Note: If you select this option, there is no need to edit the props.conf and transforms.conf files during Splunk data input configuration.

Use Forwarder TimeZoneOption to pass information about the time zone in which the forwarder is located.The MID Server uses this information to adjust for the time zone from which the logs arrive. This option is relevant when using Splunk Universal Forwarders.
Enable CompressionOption to send logs in compressed format.Sending logs in a compressed format minimizes the size of the data being transferred, which is important when dealing with large volumes of log data. This option is relevant when using Splunk Universal Forwarders and can only be used when SSL/TLS is enabled.

Advanced configuration

FieldDescriptionDefault values
Use SSL/TLSOption to use SSL/TLS.Note: To send logs in a compressed format, SSL/TLS must be enabled. 
Look up hostnamesOption to perform DNS lookup to resolve IPs to hostnames.false
Boss thread countThe number of threads that manage connections.1
Worker thread countThe number of threads that handle incoming data.4
Read timeout secondsThe timeout in seconds since the last read. When the timeout expires, the system closes the channel.30
Default timezoneThe default time zone of events. The system uses this default when the log does not specify a time zone.GMT
Sub sample drop ratioThe ratio of events to drop.-1
Sub sample receive ratioThe ratio of events to receive.-1
Max length in bytesThe maximum length of log messages in bytes.32766
Character encodingThe character encoding for this data input.UTF-8
Drop if queue is fullOption to discard logs if there is a load on the MID Server. 

Parent Topic:Data input configuration fields