output_type=splunk
splunkout=https://<your-splunk-HEC-endpoint>:8088/services/collector/event
output_format=json
[splunk]
hec_token=YOUR_SPLUNK_HEC_TOKEN
tls_verify=false
upload_empty_files=false
bundle_send_timeout=60
http_post_template={{range .Events}}{"sourcetype":"vmware:cb:edr:json","event":{{.EventText}}}{{end}}