<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best practices for HEC for on prem Splunk Distributed environment? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Best-practices-for-HEC-for-on-prem-Splunk-Distributed/m-p/463980#M80013</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;We have a splunk distributed environment with intermediate heavy forwarder tier and indexer tier.&lt;BR /&gt;
We need to implement HEC in our current environment which will include how to write to multiple indexes with a single token and ensure some level of resiliency.Please let me know what will be the best approach for this.&lt;/P&gt;</description>
    <pubDate>Fri, 22 May 2020 18:04:44 GMT</pubDate>
    <dc:creator>abhi04</dc:creator>
    <dc:date>2020-05-22T18:04:44Z</dc:date>
    <item>
      <title>Best practices for HEC for on prem Splunk Distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-practices-for-HEC-for-on-prem-Splunk-Distributed/m-p/463980#M80013</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;We have a splunk distributed environment with intermediate heavy forwarder tier and indexer tier.&lt;BR /&gt;
We need to implement HEC in our current environment which will include how to write to multiple indexes with a single token and ensure some level of resiliency.Please let me know what will be the best approach for this.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 18:04:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-practices-for-HEC-for-on-prem-Splunk-Distributed/m-p/463980#M80013</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2020-05-22T18:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices for HEC for on prem Splunk Distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-practices-for-HEC-for-on-prem-Splunk-Distributed/m-p/463981#M80014</link>
      <description>&lt;P&gt;Hi @abhi04&lt;/P&gt;

&lt;P&gt;Though I'm not quite sure if there's a best practice on implementing HEC for Distributed deployment, you can apply persistent queues to improve the data input process and potentially prevent data loss.&lt;/P&gt;

&lt;P&gt;Please see link below for more information regarding this:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Usepersistentqueues"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Usepersistentqueues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 18:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-practices-for-HEC-for-on-prem-Splunk-Distributed/m-p/463981#M80014</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2020-05-22T18:18:20Z</dc:date>
    </item>
  </channel>
</rss>

