All Apps and Add-ons

What are the pros and cons of using the HTTP Event Collector versus a standard TCP input feed?

a212830
Champion

Hi,

What are the pros and cons of using the HTTP Event Collector (HEC) vs. a standard TCP input feed? We are looking to take data from Kafka and/or Apache Nifi, and trying to determine the best option.

0 Karma
1 Solution

sloshburch
Splunk Employee
Splunk Employee

Don't forget the Kafka add ons. If you want a pull model there Splunk Add-on for Kafka. For a push model, I believe HEC is the recommended approach. There is also Kafka Messaging Modular Input written by a lead Splunker.

Related blog posts: http://blogs.splunk.com/?s=kafka

0 Karma

a212830
Champion

Awesome. Thanks!

0 Karma

jkat54
SplunkTrust
SplunkTrust

i converted this to an answer, please mark it as such.

jagadeeshm
Contributor

This practice was discouraged in Stackoverflow, so I added it to only comments. But, love to get few reputations on this as well. Thanks!

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...