Dashboards & Visualizations

Can I generate the HTTP Event Collector token on the Heavy Forwarder or Search Head?

sarnagar
Contributor

Where to set Splunk HTTP Event collector on which instance of Splunk?

Can I generate this HTTP Event Collector token on the Heavy Forwarder or Search Head?

When the application writes the data to splunk, will it write to the Heavy Forwarder?

0 Karma

fabiocaldas
Contributor

Hi sarnagar,

I'm using a cluster of Heavy Forwarders as HEC endpoints and I'm controlling it from master. I set my Heavy Forwarder to be a deployment client and I distribute HEC token from master to all of them !!

0 Karma

somesoni2
Revered Legend

You can generate/setup HTTP event Collector on Heavy forwarder. (can do in Search Head too but setting up on HF will reduce additional load on SH).

tkomatsubara_sp
Splunk Employee
Splunk Employee

See "Splunk 6.x Dashboard Examples" (Ver 6.0)
https://splunkbase.splunk.com/app/1603/

In the dashboard, you can find "Default Environment Tokens".
I didn't try, but it looks worth while to try.
For example: $env:instance_type$ = Splunk instance types

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...