Hi All,
Could you please help me with the query regarding collecting data using the HTTP Event Collector? I am trying to collect logs from F5 appliances using HEC method. The basic architecture will look like below:
F5 appliances ----> Load Balancer ----> Heavy Forwarder (where HEC will be configured) ----> Indexers
Now, my query exactly is, how to specify folder or path name to store logs on Heavy forwarder before being sent to Indexers? Any documentation or help is much appreciated.
Thanks in advance.
HEC doesn't store files on disk. You should have the HF setup to receive HEC and have an appropriate outputs to point to your indexing layer.
http://dev.splunk.com/view/event-collector/SP-CAAAE6M
http://docs.splunk.com/Documentation/Splunk/6.6.3/Data/UsetheHTTPEventCollector
HEC doesn't store files on disk. You should have the HF setup to receive HEC and have an appropriate outputs to point to your indexing layer.
http://dev.splunk.com/view/event-collector/SP-CAAAE6M
http://docs.splunk.com/Documentation/Splunk/6.6.3/Data/UsetheHTTPEventCollector
Hi @starcher,
Thank you for providing me the document links. So a typical configuration looks like as below:
in the splunk_httpinput app,
[http://F5_Analytics]
description = Token to get the logs from F5 iApp
disabled = 0
index = f5_ltm
sourcetype = f5_iapp_logs
token = xxxxxxxxxx
outoputgroup = f5
and use this outputgroup in outputs.conf of HF. Please correct me if I am wrong.
Thanks in advance.
That's correct!
Thank you very much @nickhillscpl.