Dashboards & Visualizations

Is it possible to create a custom API token for the HTTP Event Collector?

mholden37
Engager

Is it possible to create a custom API token for the HTTP Event Collector?

I need to use a token from the other system in order for the integration to work and I want to know if I can hard code my http input to use that token. The token that I would be is a different format from the format that Splunk randomly generates.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

@mholden37: I understand that the other system generates a token but it sounds to me like the token is meant for a different purpose. What has led you to believe the token is the one Splunk needs for HEC? Please provide specific links to the related token documentation from that other system (the one sending data to Splunk).

0 Karma

mholden37
Engager

Yes our environment is self-managed in AWS.

We need to hard code a token from another system because they generate a token that needs to be passed. We have already tried and have not gotten any data in.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Let us know the following so we can help out:

  • Why do you need to hard code a token from another system? It seems odd that the other system already has this arbitrary field defined. We should make sure your not conflating two different things from different solutions that might have the same name.
  • What have you tried already and what was the result? Any error messages? Any data coming in at all? (please make sure you're testing this out in a lab or your local instance).
0 Karma

sloshburch
Splunk Employee
Splunk Employee

I see you tagged splunk-cloud but I believe your environment is NOT splunk-cloud (self-managed in AWS). Right?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...