All Apps and Add-ons

Splunk MINT: How can i set up duplicated HTTP Event Collector server? (Active - Active)

sky9214
Engager

I want to send the Splunk MINT event log to each Http Event Collector?

Is there a way to set up two tokens on SDK?

0 Karma

croyal_splunk
Splunk Employee
Splunk Employee

You cannot set up 2 tokens on the same project integrated with a MINT SDK. This will not work.

0 Karma

gjanders
SplunkTrust
SplunkTrust

Your question appears to be slightly confusing, you refer to a duplicated HTTP event collector server, however the HTTP event collector is just another Splunk input, therefore the only way to run an active/active scenario would be 2 universal forwarders or 2 heavy forwarders. It would not make sense to run multiple http event collector ports on the same instance of Splunk.

The latter part of your question mentions two tokens on the SDK, I assume your again referring to the HTTP event collector ? You would use the same token on 2 forwarders if you were doing active/active, and then you would add additional tokens if required.

The inputs.conf documentation is here refer to the http event collector section. Or refer to the http event collector documentation

You will need something to load balance between the 2 servers, I use a load balancer server to distribute traffic to 2 heavy forwarders, however you could also do this using universal forwarders as per this Splunk blog post comparing heavy vs universal forwarders.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...