Dashboards & Visualizations

Single HEC token or multiple HEC token

keishamtcs
Explorer

Hi,

We have around 15 different applications for which we are going to use HEC to collect data. There are two heavy forwarders on which HEC will be configured and manage by a deployment server.

1) Should i use different token for each application or Single token for sending data ?
2) How do i configure HA between the two heavy forwarders. If one heavy forwarder goes 2nd heavy forwarder will send the data ?

Regards

0 Karma

harsmarvania57
Ultra Champion

Hi,

  1. I'll suggest to use different HEC tokens for different apps but it is purely depend on your environment and customer to customer basis.
  2. You can use loadbalancer in between HF and applications to distribute HEC load between different HF (Have a look at docs http://dev.splunk.com/view/event-collector/SP-CAAAE73#scen3 ) but make sure that you need to use same token in both the HF for this functionality.
0 Karma

dkeck
Influencer

HI,

I am not quite sure about Nr1. I saw environments where they used a new token for each HEC connection. This might be more secure (?) or just neccesarry.

to Nr2. there is no real HA for HF, you could set up your Universal Forwardes to send to both HF. UF would load balacing to the two HF than., but for your case, with HEC this is not an option.

0 Karma

keishamtcs
Explorer

Hi,

Thanks for the response.

For the 2nd point, we are not using UF. Instead it is Serilog which uses a script to send data to splunk.
Do we use a load balancer to distribute the load or modify the script to send the data to both the servers?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...