All Apps and Add-ons

HEC token for cloud and Enterprise both

splunkdivya
Explorer

Hi Splunkers,

I need to send data through HEC token to on-prem as well as Cloud splunk instance.

Please help me with some pointers.

Thanks in advance

0 Karma

manjunathmeti
Champion

Please check this link: https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector. It contains all the steps to create token for both Splunk Enterprise and Splunk cloud.

0 Karma

splunkdivya
Explorer

Hey @manjunathmethi, I need same single token for sending data simultaneously on the two instances.

0 Karma

manjunathmeti
Champion

@splunkdivya On Splunk cloud you can Enable HTTP Event Collector and create an Event Collector token. You can use same collection token ID in outputs.conf in app 'splunk_httpinput' ($SPLUNK_HOME/etc/apps/splunk_httpinput/local/) on on-prem splunk.

# Default settings
[http]
disabled = 0
port = 8088

[http://test_data]
description = HTTP event collector token for collecting data.
disabled = 0
index = main
indexes = main
sourcetype = test
token = <TOKEN>
0 Karma
Get Updates on the Splunk Community!

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...