Dashboards & Visualizations

Is it possible to create a custom API token for the HTTP Event Collector?

mholden37
Engager

Is it possible to create a custom API token for the HTTP Event Collector?

I need to use a token from the other system in order for the integration to work and I want to know if I can hard code my http input to use that token. The token that I would be is a different format from the format that Splunk randomly generates.

0 Karma

sloshburch
Ultra Champion

@mholden37: I understand that the other system generates a token but it sounds to me like the token is meant for a different purpose. What has led you to believe the token is the one Splunk needs for HEC? Please provide specific links to the related token documentation from that other system (the one sending data to Splunk).

0 Karma

mholden37
Engager

Yes our environment is self-managed in AWS.

We need to hard code a token from another system because they generate a token that needs to be passed. We have already tried and have not gotten any data in.

0 Karma

sloshburch
Ultra Champion

Let us know the following so we can help out:

  • Why do you need to hard code a token from another system? It seems odd that the other system already has this arbitrary field defined. We should make sure your not conflating two different things from different solutions that might have the same name.
  • What have you tried already and what was the result? Any error messages? Any data coming in at all? (please make sure you're testing this out in a lab or your local instance).
0 Karma

sloshburch
Ultra Champion

I see you tagged splunk-cloud but I believe your environment is NOT splunk-cloud (self-managed in AWS). Right?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...