We are planning on on-boarding several apps into Splunk using HEC.
Does anyone know if there are any limits on the number of tokens Splunk supports per server?
I know there will be connection/throughput limitations, but I was asked about the number of tokens,
and I couldn't find that documented anywhere.
Is there anyone out there that has a large number of tokens deployed?
The [http_input] stanza in the $SPLUNK_HOME/etc/system/default/limits.conf file controls HTTP Event Collector metrics data logging.
Note: For information about all HTTP Event Collector-related parameters, including those not related to metrics, see the [http_input] stanza documentation on limits.conf in the Splunk Enterprise Admin Manual.
[http_input] # the max number of tokens reported by logging input metrics max_number_of_tokens = 10000
the interval (in seconds) of logging input metrics report