All Apps and Add-ons

HEC token for cloud and Enterprise both

splunkdivya
Explorer

Hi Splunkers,

I need to send data through HEC token to on-prem as well as Cloud splunk instance.

Please help me with some pointers.

Thanks in advance

0 Karma

manjunathmeti
Champion

Please check this link: https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector. It contains all the steps to create token for both Splunk Enterprise and Splunk cloud.

0 Karma

splunkdivya
Explorer

Hey @manjunathmethi, I need same single token for sending data simultaneously on the two instances.

0 Karma

manjunathmeti
Champion

@splunkdivya On Splunk cloud you can Enable HTTP Event Collector and create an Event Collector token. You can use same collection token ID in outputs.conf in app 'splunk_httpinput' ($SPLUNK_HOME/etc/apps/splunk_httpinput/local/) on on-prem splunk.

# Default settings
[http]
disabled = 0
port = 8088

[http://test_data]
description = HTTP event collector token for collecting data.
disabled = 0
index = main
indexes = main
sourcetype = test
token = <TOKEN>
0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...