<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTP Event collector Log ingestion in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/483168#M82770</link>
    <description>&lt;P&gt;Hi , I am trying to configure HTTP event collector for log ingestion i have few questions ?&lt;/P&gt;

&lt;P&gt;I am hosting HEC on my HF .&lt;BR /&gt;
A user is running application on a application which is on Linux VM and the logs are in JSON format.&lt;/P&gt;

&lt;P&gt;Can i just create a HEC token and give it to them for deploying it on their code ?&lt;/P&gt;

&lt;P&gt;Or do i need to open Firewall connection to their server and my HF ?&lt;/P&gt;

&lt;P&gt;What port the user need to open the firewall  Is it servername:8088 port ?&lt;/P&gt;

&lt;P&gt;If i need to open firewall port is it enough to open for only HF or indexers too ?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2020 20:28:15 GMT</pubDate>
    <dc:creator>ram254481493</dc:creator>
    <dc:date>2020-01-14T20:28:15Z</dc:date>
    <item>
      <title>HTTP Event collector Log ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/483168#M82770</link>
      <description>&lt;P&gt;Hi , I am trying to configure HTTP event collector for log ingestion i have few questions ?&lt;/P&gt;

&lt;P&gt;I am hosting HEC on my HF .&lt;BR /&gt;
A user is running application on a application which is on Linux VM and the logs are in JSON format.&lt;/P&gt;

&lt;P&gt;Can i just create a HEC token and give it to them for deploying it on their code ?&lt;/P&gt;

&lt;P&gt;Or do i need to open Firewall connection to their server and my HF ?&lt;/P&gt;

&lt;P&gt;What port the user need to open the firewall  Is it servername:8088 port ?&lt;/P&gt;

&lt;P&gt;If i need to open firewall port is it enough to open for only HF or indexers too ?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 20:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/483168#M82770</guid>
      <dc:creator>ram254481493</dc:creator>
      <dc:date>2020-01-14T20:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event collector Log ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/483169#M82771</link>
      <description>&lt;P&gt;You can give them the HEC token you will generate from the HF and make sure  HEC/HEC Token is enabled, it is also good if you can provide them  the index name and sourcetype they will use. You need to make sure they can talk to your HF and allow port  8088 (default port).You dont need to enable port 8088 on indexers since your HEC receiver is the HF and it will forward the data to the indexers with listening port 9997(default port).&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 04:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/483169#M82771</guid>
      <dc:creator>jarizeloyola</dc:creator>
      <dc:date>2020-01-15T04:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event collector Log ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/483170#M82772</link>
      <description>&lt;P&gt;Sure so if they cant talk to my HF over port 8088 means they need to open firewall connectivity right ?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 14:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/483170#M82772</guid>
      <dc:creator>ram254481493</dc:creator>
      <dc:date>2020-01-16T14:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event collector Log ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/530125#M89259</link>
      <description>&lt;P&gt;An answer to this question would actually be fantastic.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 19:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-collector-Log-ingestion/m-p/530125#M89259</guid>
      <dc:creator>webesplunkin4</dc:creator>
      <dc:date>2020-11-19T19:24:13Z</dc:date>
    </item>
  </channel>
</rss>

