All Apps and Add-ons

Would there be any suggestions on properly forwarding HEC logs from heavy forwarder to indexer?

kristen
Explorer

I have configured connection between the heavy forwarder and indexer. Also I created a custom index on the indexer.

When I configure HEC on the heavy forwarder, I suppose to be able to select index created on the indexer. However, I cannot select the custom index from the heavy forwarder.

Would there be any suggestions on properly forwarding HEC logs from heavy forwarder to indexer? Thank you.

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kristen,

yes it's correct, from the GUi of an heavy Forwarder isn't possible to address a remote index.

You have two solutions:

  • after the HEC configuration, manually add the index definition in the inputs.conf (this requires Splunk restart),
  • create a local index with the same name of the remote one, only to have it in the GUI list.

I hint to add this problem to Splunk Ideas (ideas.splunk.com).

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...