Dashboards & Visualizations

Recreate HEC token on server


My sandbox splunk instance crashed and I am not able to restore the data. I need to restore my Splunk HEC tokens and settings. Whenever I try to create a new HEC token, Splunk generates a random HEC token id. How do i create a new HEC token with a predefined token id of my choice?

Is it possible to do this through a curl command? If so can you provide instructions or example?

0 Karma


I'm not aware of a way to programmatically create tokens with a specific value but Splunk explains the configuration format at http://docs.splunk.com/Documentation/Splunk/7.1.1/Data/UseHECusingconffiles and editing the config file manually should work fine. I would probably create the tokens in the GUI, then locate the appropriate inputs.conf on the file system (probably $SPLUNK_HOME/etc/apps/launcher/local/inputs.conf) and edit the values there. Restarting Splunk will make the changes take effect. Good luck!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...