> For the complete documentation index, see [llms.txt](https://docs.pentaho.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pentaho.com/pdia-data-integration/9.3-data-integration/pdi-transformation-steps-reference-overview/splunk-output/options-splunk-output/event-tab.md).

# Event tab

![Event tab, Splunk Output](/files/1NQASC7D5bCd19tHc10G)

In this tab, you can define the following event properties and options, as described in the table below.

| Option                  | Description                                                                                                                                                                                                                                                                                                                                                             |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Index to write to**   | Specifies the Splunk index where the events are stored. Usually, this is the main index. Check your Splunk server for a list of available indices. This field can be a parameter with incoming fields (**?{\<Field>}**) or transformation parameters **(${Parameter}**).                                                                                                |
| **Host**                | Indicates the hostname of the original event host. If you want to gather data from a router and write it to Splunk, use the router's host name. This field can be a parameter with incoming fields (**?{\<Field>}**) or transformation parameters (**${Parameter}**).                                                                                                   |
| **Source type**         | Indicates the format type of the event data. The list of known source types appears [here](http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/Listofpretrainedsourcetypes). To define a new format, follow [these instructions](http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles). |
| **Source**              | Indicates the source of the event data. See [Splunk documentation](http://docs.splunk.com/Splexicon:Sourcetype) for more details.                                                                                                                                                                                                                                       |
| **Custom Splunk event** | If checked, enables the Splunk Event Data option and allows you to customize the data coming into Splunk. This is useful if you want to write a different format than the default, which is name value pairs separated by newline characters.                                                                                                                           |
| **Splunk Event Data**   | Allows you to specify customized event text. This field can be a parameter with incoming fields (**?{\<Field>}**) or transformation parameters (**${Parameter}**).                                                                                                                                                                                                      |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.pentaho.com/pdia-data-integration/9.3-data-integration/pdi-transformation-steps-reference-overview/splunk-output/options-splunk-output/event-tab.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
