Deployment Architecture

Enable Deployment and HEC tokens in Global settings

SecurityFeller
Explorer

We are generating HEC tokens on a deployment server and pushing them out to the HECs. 

HEC tokens are disabled by default on the HECs and the deployment server and need to be enabled in global settings. 

What I've done so far is:

-authorize.conf, this is for user tokens and isn't working for HEC tokens

-the CLI command for token enable isn't working because it's not enabled globally

-inputs.conf has [http] disabled=0

 

The only thing that has worked is enabling it via the UI. Is there a way to enable these over CLI?

0 Karma
1 Solution

SecurityFeller
Explorer

Solved. Splunk did not take conf file enablement on creation. It must be modified afterwards. 

View solution in original post

SecurityFeller
Explorer

Solved. Splunk did not take conf file enablement on creation. It must be modified afterwards. 

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...