splunk-hec-handler
A Python logging handler to sends logs to Splunk using HTTP event collector (HEC)
Decision gist · record as of 2026-08-14
Yes, if you are already committed to Splunk and need straightforward Python logging integration. The package is simple, has low install friction, and carries a permissive license. However, the abandoned maintenance status (last update 2023-02-16) means you should verify compatibility with your Splunk version and Python runtime before production deployment, and be prepared to maintain a fork if critical issues arise.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a running Splunk instance with HTTP Event Collector enabled and a valid HEC token.
- Low install friction with a single runtime dependency (requests).
- However, the package is abandoned—last commit was 2023-02-16 and no updates have been released since.
License · maintenance · safety
MIT License (permissive) — MIT License (permissive) means you can use, modify, and distribute this package freely in commercial or private projects with minimal restrictions.
last release 2023-02-16 (1275 days) · last repo commit 2023-02-16 · 11 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 99,999 downloads/mo, #13,006 on PyPI
Alternatives
Verify before relying
pip install splunk-hec-handler
import logging
from splunk_hec_handler import SplunkHecHandler
logger = logging.getLogger('example')
logger.setLevel(logging.DEBUG)
splunk_handler = SplunkHecHandler('splunkfw.domain.tld',
'EA33046C-6FEC-4DC0-AC66-4326E58B54C3',
port=8888, proto='https', ssl_verify=True)
logger.addHandler(splunk_handler)
logger.info("Test message")- Whether the package works reliably with modern Python versions (3.9+) despite classifiers only listing up to 3.8.
- Current compatibility with recent versions of the requests dependency.
- Whether abandoned status impacts security or compatibility with current Splunk versions.
What it is and what it does
This package provides a Python logging handler that sends log records to Splunk via its HTTP Event Collector (HEC) API. It wraps the standard Python logging framework to route messages directly into Splunk as JSON events, allowing you to centralize application logs in Splunk without separate log file collection. The handler automatically timestamps events, preserves dictionary objects as structured JSON, and supports custom fields and metadata overrides through a 'fields' key in log records.
The handler depends only on requests for HTTP communication and is designed to work across Linux, macOS, and Windows. It supports both HTTP and HTTPS connections, with optional SSL verification control for self-signed certificates. String log messages are converted to JSON with 'log_level' and 'message' keys, while dictionary objects are logged as-is, making it flexible for both simple text logging and structured event logging.
Use it for
- Centralize application logs from Python services into Splunk for monitoring and analysis.
- Send structured event data (dicts with custom fields) to Splunk indexes for security or operational intelligence.
- Route logs to multiple Splunk indexes by configuring different handlers with different tokens or index settings.
- Add custom metadata fields (host, source, sourcetype) to log events at the application level.
- Integrate Python application logging with existing Splunk infrastructure without external log collectors.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already committed to Splunk and need straightforward Python logging integration.
The package is simple, has low install friction, and carries a permissive license. However, the abandoned maintenance status (last update 2023-02-16) means you should verify compatibility with your Splunk version and Python runtime before production deployment, and be prepared to maintain a fork if critical issues arise.
Install
splunk-hec-handler on PyPI
Before you install
Low install friction with a single runtime dependency (requests). However, the package is abandoned—last commit was 2023-02-16 and no updates have been released since. Maintenance status should be a consideration for production use.
Requires a running Splunk instance with HTTP Event Collector enabled and a valid HEC token.
License in practice
MIT License (permissive) means you can use, modify, and distribute this package freely in commercial or private projects with minimal restrictions.
Quickstart
pip install splunk-hec-handler
import logging
from splunk_hec_handler import SplunkHecHandler
logger = logging.getLogger('example')
logger.setLevel(logging.DEBUG)
splunk_handler = SplunkHecHandler('splunkfw.domain.tld',
'EA33046C-6FEC-4DC0-AC66-4326E58B54C3',
port=8888, proto='https', ssl_verify=True)
logger.addHandler(splunk_handler)
logger.info("Test message")
Verify before relying
- Whether the package works reliably with modern Python versions (3.9+) despite classifiers only listing up to 3.8.
- Current compatibility with recent versions of the requests dependency.
- Whether abandoned status impacts security or compatibility with current Splunk versions.
Package facts
| License | MIT License permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagerequests |
| Maintenance | Abandoned 1,275 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 99,999 / month, #13,006 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 2.7Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Topic :: System :: Logging |
Evidence: splunk_hec_handler-1.2.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “http event collector”
- splunk-hec-handlerIntegrates Python logging with Splunk's HTTP Event Collector (HEC) to…
- splunk-handlerA Python logging handler that sends log events to a Splunk Enterprise…
- snowplow-trackerSends event data from Python applications to Snowplow analytics…
Give your agent the search over MCP, or paste the wish link into any chat.
More Logging packages
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
Formats Python logging output as JSON, making logs machine-readable for parsing and ingestion into log aggregation tools.
Install it if you need JSON-formatted logs for aggregation or centralized monitoring.
structlog is a structured logging library that lets you emit logs as dictionaries with flexible output formats (JSON, logfmt, console) and integrates with Python's standard logging or runs standalone.
Install it if your application needs JSON or logfmt output, or if you want to add rich context to logs without string formatting.
Loguru provides a pre-configured logger that replaces Python's standard logging with a simpler, zero-boilerplate interface for writing log messages to stderr, files, or custom handlers.
Install it if you want logging to feel natural but with the power, structure that production code needs.
Adds colored output to Python's standard logging module using ANSI escape sequences, with automatic fallback support for Windows terminals.
However, it is abandoned and receives no maintenance, so it will not adapt to future Python changes or platform updates.
wandb is a machine learning experiment tracking and visualization platform that logs metrics, hyperparameters, datasets, and models to a centralized dashboard for monitoring and comparing training runs.
Install it if you need centralized experiment tracking, comparison, and visualization for machine learning projects; skip it if you prefer local-only logging or have…
See also splunk-handler · json-logging · python-logging-loki · mo-logs · signalfx · loki-logger-handler · splunk-sdk · splunk-opentelemetry · pygelf · signalflow-client-python