<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newbie question: Push changes from UI to Indexers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-question-Push-changes-from-UI-to-Indexers/m-p/567137#M100764</link>
    <description>&lt;P&gt;When you set up HEC on the search head, Splunk added a stanza to inputs.conf for you.&amp;nbsp; Copy that stanza to indexes.conf in an app and install that app on your indexers (use the Cluster Manager if you have one).&amp;nbsp; All indexers should then have the same HEC settings.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 17:03:12 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-09-15T17:03:12Z</dc:date>
    <item>
      <title>Newbie question: Push changes from UI to Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-question-Push-changes-from-UI-to-Indexers/m-p/567128#M100763</link>
      <description>&lt;P&gt;I used&amp;nbsp;&lt;A href="https://github.com/Azure/splunk-enterprise" target="_self"&gt;Azure/Splunk Enterprise&lt;/A&gt;&amp;nbsp;deployment to set up Splunk on my Azure instance.&lt;/P&gt;&lt;P&gt;I then did this:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Settings &amp;gt; Show All Settings&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Create an index via&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Indexes&lt;/STRONG&gt; (Type: Events, ensured it is&amp;nbsp;&lt;EM&gt;enabled&lt;/EM&gt;)&lt;/LI&gt;&lt;LI&gt;Create an HTTP Event Collector via&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Data Inputs &amp;gt; HTTP Event Collector&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Attempt to run a curl to the&amp;nbsp;&lt;STRONG&gt;hec&lt;/STRONG&gt;&amp;nbsp;Public IP Address Azure Resource that was created&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I get:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;{"text":"Invalid token","code":4}&lt;/P&gt;&lt;P&gt;Based on what I was reading, I need to push the change out to the&amp;nbsp;&lt;EM&gt;Indexers&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;So here's my questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can I do that through the UI?&lt;/LI&gt;&lt;LI&gt;Do I need to update each of the indexers manually?&lt;/LI&gt;&lt;LI&gt;Is there an alternative location for setting this up I am missing?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks for helping a newbie!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 14:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-question-Push-changes-from-UI-to-Indexers/m-p/567128#M100763</guid>
      <dc:creator>ssdarkside2</dc:creator>
      <dc:date>2021-09-15T14:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie question: Push changes from UI to Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-question-Push-changes-from-UI-to-Indexers/m-p/567137#M100764</link>
      <description>&lt;P&gt;When you set up HEC on the search head, Splunk added a stanza to inputs.conf for you.&amp;nbsp; Copy that stanza to indexes.conf in an app and install that app on your indexers (use the Cluster Manager if you have one).&amp;nbsp; All indexers should then have the same HEC settings.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 17:03:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-question-Push-changes-from-UI-to-Indexers/m-p/567137#M100764</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-15T17:03:12Z</dc:date>
    </item>
  </channel>
</rss>

