Dashboards & Visualizations

Can I generate the HTTP Event Collector token on the Heavy Forwarder or Search Head?


Where to set Splunk HTTP Event collector on which instance of Splunk?

Can I generate this HTTP Event Collector token on the Heavy Forwarder or Search Head?

When the application writes the data to splunk, will it write to the Heavy Forwarder?

0 Karma


Hi sarnagar,

I'm using a cluster of Heavy Forwarders as HEC endpoints and I'm controlling it from master. I set my Heavy Forwarder to be a deployment client and I distribute HEC token from master to all of them !!

0 Karma

Revered Legend

You can generate/setup HTTP event Collector on Heavy forwarder. (can do in Search Head too but setting up on HF will reduce additional load on SH).

Splunk Employee
Splunk Employee

See "Splunk 6.x Dashboard Examples" (Ver 6.0)

In the dashboard, you can find "Default Environment Tokens".
I didn't try, but it looks worth while to try.
For example: $env:instance_type$ = Splunk instance types

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...