<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where do I enable HTTP Event Collector (HEC) and create a new token in an environment with both search head and indexer clustering? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220336#M13683</link>
    <description>&lt;P&gt;jmmccollum, we haven't started our HEC effort yet. Hopefully, someone else can help answer your questions.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2016 03:44:55 GMT</pubDate>
    <dc:creator>flee</dc:creator>
    <dc:date>2016-09-22T03:44:55Z</dc:date>
    <item>
      <title>Where do I enable HTTP Event Collector (HEC) and create a new token in an environment with both search head and indexer clustering?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220332#M13679</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have a Splunk Enterprise environment that has separate tiers that are clustered; Search Heads and Indexers.  Where/which tier do I enable HEC on and create tokens?  Search Heads or Indexers?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 17:18:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220332#M13679</guid>
      <dc:creator>flee</dc:creator>
      <dc:date>2016-08-09T17:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I enable HTTP Event Collector (HEC) and create a new token in an environment with both search head and indexer clustering?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220333#M13680</link>
      <description>&lt;P&gt;There are several deployment strategies outlined in the docs:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE73"&gt;http://dev.splunk.com/view/event-collector/SP-CAAAE73&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you have a large enough deployment where you have search and indexing tiers, you probably also want to split out the http event collection service onto one or more forwarders. &lt;/P&gt;

&lt;P&gt;You can use a single forwarder to receive HEC events and generate keys.  That's probably the simplest way to get started.  &lt;/P&gt;

&lt;P&gt;If you decide to scale out, you can add additional forwarders and use the deployment server to generate keys and automatically distribute them among the forwarders.  Use a load balancer to distribute requests among your forwarders.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 19:23:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220333#M13680</guid>
      <dc:creator>Jeremiah</dc:creator>
      <dc:date>2016-08-09T19:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I enable HTTP Event Collector (HEC) and create a new token in an environment with both search head and indexer clustering?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220334#M13681</link>
      <description>&lt;P&gt;Thank you Jeremiah!  The doc link helps as well.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 21:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220334#M13681</guid>
      <dc:creator>flee</dc:creator>
      <dc:date>2016-08-09T21:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I enable HTTP Event Collector (HEC) and create a new token in an environment with both search head and indexer clustering?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220335#M13682</link>
      <description>&lt;P&gt;What is the best way to manage tokens in a clustered indexer environment where we want to run HEC on the indexers?  Can we run a deployment server just for token management while the cluster master manages everything else?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 17:51:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220335#M13682</guid>
      <dc:creator>jmmccollum</dc:creator>
      <dc:date>2016-09-21T17:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I enable HTTP Event Collector (HEC) and create a new token in an environment with both search head and indexer clustering?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220336#M13683</link>
      <description>&lt;P&gt;jmmccollum, we haven't started our HEC effort yet. Hopefully, someone else can help answer your questions.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 03:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220336#M13683</guid>
      <dc:creator>flee</dc:creator>
      <dc:date>2016-09-22T03:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I enable HTTP Event Collector (HEC) and create a new token in an environment with both search head and indexer clustering?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220337#M13684</link>
      <description>&lt;P&gt;Hi jmmccollum, these following Splunk answers might help you: &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/685621/hec-and-indexer-clustering.html"&gt;https://answers.splunk.com/answers/685621/hec-and-indexer-clustering.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/734827/how-to-deploy-hec-and-token-to-indexers-in-a-clust-1.html"&gt;https://answers.splunk.com/answers/734827/how-to-deploy-hec-and-token-to-indexers-in-a-clust-1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 16:40:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-do-I-enable-HTTP-Event-Collector-HEC-and-create-a-new/m-p/220337#M13684</guid>
      <dc:creator>marend_splunk</dc:creator>
      <dc:date>2019-04-01T16:40:50Z</dc:date>
    </item>
  </channel>
</rss>

