Where to set Splunk HTTP Event collector on which instance of Splunk?
Can I generate this HTTP Event Collector token on the Heavy Forwarder or Search Head?
When the application writes the data to splunk, will it write to the Heavy Forwarder?
I'm using a cluster of Heavy Forwarders as HEC endpoints and I'm controlling it from master. I set my Heavy Forwarder to be a deployment client and I distribute HEC token from master to all of them !!
See "Splunk 6.x Dashboard Examples" (Ver 6.0)
In the dashboard, you can find "Default Environment Tokens".
I didn't try, but it looks worth while to try.
For example: $env:instance_type$ = Splunk instance types