Splunk · Arazzo Workflow
Splunk Ingest Raw Data then Search for It
Version 1.0.0
Send raw text to HEC, then run an SPL search and poll it to confirm the data landed.
View Spec
View on GitHub
AnalyticsData AnalysisLoggingMachine DataMonitoringObservabilityPlatformSecuritySIEMArazzoWorkflows
Provider
Workflows
raw-ingest-and-search
Send raw data to HEC, then dispatch and poll a search that finds it.
Posts raw text to the HEC raw collector with source and index overrides, then dispatches an SPL search against that index, polls the job to DONE, and reads the results to verify the data is searchable.
1
sendRaw
sendRawEvent
Post raw text to the HEC raw endpoint with index, source, and sourcetype overrides.
2
createJob
createSearchJob
Dispatch an SPL search against the target index to confirm the ingested data is searchable.
3
pollJob
getSearchJob
Poll the search job until its dispatchState reports DONE.
4
getResults
getSearchResults
Retrieve the search results to confirm the raw data was indexed and is now searchable.
Source API Descriptions
Arazzo Workflow Specification
Work with this as data
Every workflow here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for arazzo workflows
4 MCP tools reach this
find_arazzoBrowse and filter every workflow in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/splunk-raw-ingest-and-search-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.