Provider access stays separate from application control.
01
Current evidence remains pull-based
Authorized customers can retrieve gateway evidence through the control API now. AI Gateway HQ does not claim that a native Splunk event was accepted, indexed, retried, or acknowledged before the HEC delivery path exists.
02
Delivery needs more than an HTTP 200
Splunk documents token authentication and optional indexer acknowledgment with a separate acknowledgment query. The planned exporter must preserve an exact checkpoint and handle retryable capacity responses without duplicating an evidence record.
03
Keep each destination tenant-scoped
The planned connection will bind its HEC endpoint, encrypted token, allowed evidence scope, retry state, and checkpoint to one customer organization. Release requires failure-path and cross-tenant isolation tests, not only a successful sample event.
Current shared controls
Status determines what can be configured.
Write-only, encrypted BYOK for implemented provider connections Stable model aliases and protocol-eligible route targets Organization and key budgets, RPM, TPM, and concurrency hard limits Observe, Shadow, Enforce, reason codes, and metadata-only evidence
This connection is not implemented. The controls above describe the gateway baseline, not availability for this planned integration.
Applications keep a stable gateway URL and model alias while an administrator changes eligible provider accounts and models.
Implemented boundary
Only documented protocols become eligible.
No native Splunk delivery setup is exposed today. Retrieve evidence through the authenticated control API until the HEC sender, secret boundary, retry policy, acknowledgment checkpoint, and tenant-isolated delivery tests are released.