The target API expects entries to come via a specific URL endpoint and works with json files.
I managed to create an entry in the system with curl but I need Splunk to index and then forward entries in json format.
curl -X POST -H "Accept: application/json" -u "username:password" https://ENDPOINT_HOST:8081/loggingservice/security-events -d @entry.json
I am looking for the same solution. May be a custom command using Python script will help.