Splunk · Schema
HecEvent
AnalyticsData AnalysisLoggingMachine DataMonitoringObservabilityPlatformSecuritySIEM
Properties
| Name | Type | Description |
|---|---|---|
| time | string | Event timestamp in epoch time (seconds since 1970-01-01). If omitted, Splunk uses the current time. |
| host | string | Hostname or IP address of the event source |
| source | string | Source of the event |
| sourcetype | string | Source type for the event |
| index | string | Destination index for the event |
| event | string | The event data. Can be a string or a JSON object. This is the actual data payload to be indexed. |
| fields | object | Additional metadata fields to associate with the event. These fields are indexed as metadata and can be searched. |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "HecEvent",
"type": "object",
"properties": {
"time": {
"type": "string",
"description": "Event timestamp in epoch time (seconds since 1970-01-01). If omitted, Splunk uses the current time."
},
"host": {
"type": "string",
"description": "Hostname or IP address of the event source"
},
"source": {
"type": "string",
"description": "Source of the event"
},
"sourcetype": {
"type": "string",
"description": "Source type for the event"
},
"index": {
"type": "string",
"description": "Destination index for the event"
},
"event": {
"type": "string",
"description": "The event data. Can be a string or a JSON object. This is the actual data payload to be indexed."
},
"fields": {
"type": "object",
"description": "Additional metadata fields to associate with the event. These fields are indexed as metadata and can be searched."
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/splunk-enterprise-rest-hec-event"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.