splunk-amazon-kinesis-firehose-setup

Render and validate Amazon Kinesis Firehose to Splunk HEC onboarding assets.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-amazon-kinesis-firehose-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-amazon-kinesis-firehose-setup
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-amazon-kinesis-firehose-setup
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-amazon-kinesis-firehose-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This skill renders and validates the Amazon Kinesis Firehose to Splunk HEC onboarding artifacts without exposing tokens or requiring immediate direct Splunk resource creation, enabling safe handoffs to token management and owner teams.

Core Features & Use Cases

Render-first workflow for Amazon Kinesis Firehose delivery into Splunk HEC. The skill emits HEC handoffs, destination settings, IAM and backup stubs, delivery metric checks, validation SPL, and readiness evidence, and delegates HEC token work to the splunk-hec-service-setup skill while AWS resource provisioning remains with the AWS owner.

Quick Start

Render the Firehose setup assets and then delegate token creation to the HEC service setup.

Frequently Asked Questions about splunk-amazon-kinesis-firehose-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I render Amazon Kinesis Firehose to Splunk HEC onboarding assets?

To render Amazon Kinesis Firehose to Splunk HEC assets, use a render-first workflow that emits destination settings, IAM stubs, backup templates, and validation SPL. It supports source profiles like cloudtrail, vpcflow, and cloudwatch-events without requiring immediate AWS resource creation.

What source profiles are supported for Amazon Kinesis Firehose delivery to Splunk HEC?

Supported source profiles for Firehose to Splunk HEC delivery include cloudtrail, vpcflow, cloudwatch-events, raw-json, and raw. These profiles allow you to generate specific destination settings, IAM stubs, and delivery metric checks tailored to each data source.

Does this Firehose to Splunk HEC setup render HEC tokens?

No, this Firehose to Splunk HEC setup does not render real tokens for safety. It strictly enforces this limitation by delegating all token creation and token management work to the dedicated splunk-hec-service-setup skill.

Can I provision AWS resources directly when setting up Kinesis Firehose for Splunk?

No, you cannot provision AWS resources directly when setting up Kinesis Firehose for Splunk using this approach. AWS resource provisioning remains with the AWS owner; this skill only renders and validates the onboarding artifacts for safe handoffs.

What validation checks are generated for Amazon Kinesis Firehose Splunk delivery?

Validation checks generated for Amazon Kinesis Firehose Splunk delivery include validation SPL, delivery metric checks, and readiness evidence. These checks ensure the rendered destination settings and backup templates are correctly configured before handoff.

Why use a render-first workflow for Amazon Kinesis Firehose to Splunk HEC integration?

Use a render-first workflow for Amazon Kinesis Firehose to Splunk HEC integration to safely generate onboarding artifacts without exposing tokens or requiring direct Splunk resource creation. This enables secure handoffs to token management and owner teams.