Dashboards & Visualizations

Can I generate the HTTP Event Collector token on the Heavy Forwarder or Search Head?

sarnagar
Contributor

Where to set Splunk HTTP Event collector on which instance of Splunk?

Can I generate this HTTP Event Collector token on the Heavy Forwarder or Search Head?

When the application writes the data to splunk, will it write to the Heavy Forwarder?

0 Karma

fabiocaldas
Contributor

Hi sarnagar,

I'm using a cluster of Heavy Forwarders as HEC endpoints and I'm controlling it from master. I set my Heavy Forwarder to be a deployment client and I distribute HEC token from master to all of them !!

0 Karma

somesoni2
Revered Legend

You can generate/setup HTTP event Collector on Heavy forwarder. (can do in Search Head too but setting up on HF will reduce additional load on SH).

tkomatsubara_sp
Splunk Employee
Splunk Employee

See "Splunk 6.x Dashboard Examples" (Ver 6.0)
https://splunkbase.splunk.com/app/1603/

In the dashboard, you can find "Default Environment Tokens".
I didn't try, but it looks worth while to try.
For example: $env:instance_type$ = Splunk instance types

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...