Security operations · Planned

Splunk is not currently available as a native integration.

Native HEC delivery, signing, retry, and export checkpoints are planned; evidence is currently available through the control API.

How the connection works

Provider access stays separate from application control.

01

Current evidence remains pull-based

Authorized customers can retrieve gateway evidence through the control API now. AI Gateway HQ does not claim that a native Splunk event was accepted, indexed, retried, or acknowledged before the HEC delivery path exists.

02

Delivery needs more than an HTTP 200

Splunk documents token authentication and optional indexer acknowledgment with a separate acknowledgment query. The planned exporter must preserve an exact checkpoint and handle retryable capacity responses without duplicating an evidence record.

03

Keep each destination tenant-scoped

The planned connection will bind its HEC endpoint, encrypted token, allowed evidence scope, retry state, and checkpoint to one customer organization. Release requires failure-path and cross-tenant isolation tests, not only a successful sample event.

Current shared controls

Status determines what can be configured.

Write-only, encrypted BYOK for implemented provider connections Stable model aliases and protocol-eligible route targets Organization and key budgets, RPM, TPM, and concurrency hard limits Observe, Shadow, Enforce, reason codes, and metadata-only evidence

This connection is not implemented. The controls above describe the gateway baseline, not availability for this planned integration.

Client boundary
AIGHQ_BASE_URL=https://api.aigatewayhq.com/v1
AIGHQ_API_KEY=from-your-workspace
AIGHQ_MODEL=company-approved-fast

Applications keep a stable gateway URL and model alias while an administrator changes eligible provider accounts and models.

Implemented boundary

Only documented protocols become eligible.

No native Splunk delivery setup is exposed today. Retrieve evidence through the authenticated control API until the HEC sender, secret boundary, retry policy, acknowledgment checkpoint, and tenant-isolated delivery tests are released.

HTTPS HTTP Event Collector events Token-scoped authorization Optional indexer acknowledgment checkpoints

Compatibility is bounded to the provider's current published interface. Review the provider documentation before approving a production model.