Export security events from Splunk Enterprise, Splunk Cloud, or Splunk Enterprise Security through an OTLP-capable pipeline. Preserve index, sourcetype, source, CIM fields, and raw event text.
Map Splunk metadata into attributes such as splunk.index, splunk.sourcetype, splunk.source, and event.original. Keep CIM field names alongside vendor raw fields when possible.