Dashboards & Visualizations

Recreate HEC token on server

spammenot66
Contributor

My sandbox splunk instance crashed and I am not able to restore the data. I need to restore my Splunk HEC tokens and settings. Whenever I try to create a new HEC token, Splunk generates a random HEC token id. How do i create a new HEC token with a predefined token id of my choice?

Is it possible to do this through a curl command? If so can you provide instructions or example?

0 Karma

jtacy
Builder

I'm not aware of a way to programmatically create tokens with a specific value but Splunk explains the configuration format at http://docs.splunk.com/Documentation/Splunk/7.1.1/Data/UseHECusingconffiles and editing the config file manually should work fine. I would probably create the tokens in the GUI, then locate the appropriate inputs.conf on the file system (probably $SPLUNK_HOME/etc/apps/launcher/local/inputs.conf) and edit the values there. Restarting Splunk will make the changes take effect. Good luck!

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...