All Apps and Add-ons

Splunk MINT: How can i set up duplicated HTTP Event Collector server? (Active - Active)

sky9214
Engager

I want to send the Splunk MINT event log to each Http Event Collector?

Is there a way to set up two tokens on SDK?

0 Karma

croyal_splunk
Splunk Employee
Splunk Employee

You cannot set up 2 tokens on the same project integrated with a MINT SDK. This will not work.

0 Karma

gjanders
SplunkTrust
SplunkTrust

Your question appears to be slightly confusing, you refer to a duplicated HTTP event collector server, however the HTTP event collector is just another Splunk input, therefore the only way to run an active/active scenario would be 2 universal forwarders or 2 heavy forwarders. It would not make sense to run multiple http event collector ports on the same instance of Splunk.

The latter part of your question mentions two tokens on the SDK, I assume your again referring to the HTTP event collector ? You would use the same token on 2 forwarders if you were doing active/active, and then you would add additional tokens if required.

The inputs.conf documentation is here refer to the http event collector section. Or refer to the http event collector documentation

You will need something to load balance between the 2 servers, I use a load balancer server to distribute traffic to 2 heavy forwarders, however you could also do this using universal forwarders as per this Splunk blog post comparing heavy vs universal forwarders.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...