Dashboards & Visualizations

Can I generate the HTTP Event Collector token on the Heavy Forwarder or Search Head?

sarnagar
Contributor

Where to set Splunk HTTP Event collector on which instance of Splunk?

Can I generate this HTTP Event Collector token on the Heavy Forwarder or Search Head?

When the application writes the data to splunk, will it write to the Heavy Forwarder?

0 Karma

fabiocaldas
Contributor

Hi sarnagar,

I'm using a cluster of Heavy Forwarders as HEC endpoints and I'm controlling it from master. I set my Heavy Forwarder to be a deployment client and I distribute HEC token from master to all of them !!

0 Karma

somesoni2
Revered Legend

You can generate/setup HTTP event Collector on Heavy forwarder. (can do in Search Head too but setting up on HF will reduce additional load on SH).

tkomatsubara_sp
Splunk Employee
Splunk Employee

See "Splunk 6.x Dashboard Examples" (Ver 6.0)
https://splunkbase.splunk.com/app/1603/

In the dashboard, you can find "Default Environment Tokens".
I didn't try, but it looks worth while to try.
For example: $env:instance_type$ = Splunk instance types

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...