<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I create the same HTTP event collector token for multiple indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255959#M49130</link>
    <description>&lt;P&gt;@johnprof we're working on them now&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2015 20:44:04 GMT</pubDate>
    <dc:creator>gblock_splunk</dc:creator>
    <dc:date>2015-10-01T20:44:04Z</dc:date>
    <item>
      <title>How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255955#M49126</link>
      <description>&lt;P&gt;I have three stand alone indexers in a round robin and want them to accept HTTP events via the HTTP Event Collector. How do I generate a token with the same value on all three?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 19:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255955#M49126</guid>
      <dc:creator>johnpof</dc:creator>
      <dc:date>2015-10-01T19:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255956#M49127</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/188962"&gt;@ppablo&lt;/a&gt;.&lt;/P&gt;

&lt;P&gt;The recommended way to do this is to use Deployment Server. We have documentation which will be shortly forthcoming explaining how to do this.&lt;/P&gt;

&lt;P&gt;The way it works is you have your indexers as clients of Event Collector. HTTP Event Collector has a global setting that you will configure on the deployment server "Use Deployment Server". In etc/apps/splunk_httpinput/local/inputs.conf it is the "useDeplyomentServer" &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.0/admin/Inputsconf" target="_blank"&gt;setting&lt;/A&gt; under the [http] stanza. Once you set this, the collector will write all of it's configuration to the etc/deployment_apps/splunk_httpinput folder. Any time you use the UI or API to manage tokens, the deployment server will package up the updates so that the next time the clients (indexers) poll, they will get the latest tokens. The indexers will restart and load the new tokens in a staggered fashion.&lt;/P&gt;

&lt;P&gt;There's a little bit of manual setup on the deployment server initially before you set the settings. First manually create the etc/deployment_apps/splunk_httpinput folder. Then copy the config from etc/apps/splunk_httpinput in. &lt;/P&gt;

&lt;P&gt;As I mentioned, we'll have more docs coming in the next week or so that will show how to do this.&lt;/P&gt;

&lt;P&gt;Glenn&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255956#M49127</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2020-09-29T07:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255957#M49128</link>
      <description>&lt;P&gt;Whoops sorry, I accidentally clicked accept for your answer, so sorry if you got a notification! I wasn't the one who asked the question, it was @johnpof. I'm the Answers content manager &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I just edited the post for better visibility.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255957#M49128</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-10-01T20:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255958#M49129</link>
      <description>&lt;P&gt;Hah no worries I appreciate the reply! Look forward to seeing the docs, if you remember please fire them into this post.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255958#M49129</guid>
      <dc:creator>johnpof</dc:creator>
      <dc:date>2015-10-01T20:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255959#M49130</link>
      <description>&lt;P&gt;@johnprof we're working on them now&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255959#M49130</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2015-10-01T20:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255960#M49131</link>
      <description>&lt;P&gt;does it have to be called &lt;CODE&gt;splunk_httpinput&lt;/CODE&gt;?? IIRC deployment server / splunk .conf guides recommend following an app naming convention, for which that would be bucking the trend &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 08:17:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255960#M49131</guid>
      <dc:creator>awurster</dc:creator>
      <dc:date>2015-10-14T08:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255961#M49132</link>
      <description>&lt;P&gt;Has the documentation for this been released?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 19:09:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255961#M49132</guid>
      <dc:creator>samuel_stvictor</dc:creator>
      <dc:date>2015-10-20T19:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255962#M49133</link>
      <description>&lt;P&gt;@samuel_stvictor, not yet. If you'd like to review it before we do, email me: &lt;A href="mailto:gblock@splunk.com"&gt;gblock@splunk.com&lt;/A&gt; and I can send it to you.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 19:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255962#M49133</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2015-10-20T19:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255963#M49134</link>
      <description>&lt;P&gt;Same for you @johnpof&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 19:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255963#M49134</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2015-10-20T19:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255964#M49135</link>
      <description>&lt;P&gt;Yes it does. Under deployment-apps it should be splunk_httpinput.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 19:16:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255964#M49135</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2015-10-20T19:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255965#M49136</link>
      <description>&lt;P&gt;Hi folks&lt;/P&gt;

&lt;P&gt;We just published our new documentation for distributed deployment &lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE73"&gt;here&lt;/A&gt;. We'd love your feedback!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 02:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255965#M49136</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2015-11-04T02:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255966#M49137</link>
      <description>&lt;P&gt;Love it. Great doc!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 04:51:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255966#M49137</guid>
      <dc:creator>aliakseidzianis</dc:creator>
      <dc:date>2017-01-27T04:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255967#M49138</link>
      <description>&lt;P&gt;I can't find anything in here on how it would be deployed on clustered indexers. I would assume I'd use a similar configuration pushed from master-apps, but it would be a good thing to cover in the docs!&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 13:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255967#M49138</guid>
      <dc:creator>delink</dc:creator>
      <dc:date>2017-05-26T13:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255968#M49139</link>
      <description>&lt;P&gt;i have the same question actually - is it the same method using cluster master ?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 04:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255968#M49139</guid>
      <dc:creator>Esky73</dc:creator>
      <dc:date>2017-08-02T04:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255969#M49140</link>
      <description>&lt;P&gt;Hi, Is there a way to do this without Deployment Server?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 16:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255969#M49140</guid>
      <dc:creator>ahmedn_splunk</dc:creator>
      <dc:date>2018-07-30T16:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create the same HTTP event collector token for multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255970#M49141</link>
      <description>&lt;P&gt;I have the same question -  any way to do this without Deployment Server?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 00:27:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-the-same-HTTP-event-collector-token-for-multiple/m-p/255970#M49141</guid>
      <dc:creator>sphadnis</dc:creator>
      <dc:date>2019-04-09T00:27:34Z</dc:date>
    </item>
  </channel>
</rss>

