Getting Data In

Help needed with HEC tokens

Roy_9
Motivator

Hello,

I have an index and 3 custom sourcetypes built in place, Suppose if the source wants to stream logs into Splunk, do i need to create 3 HEC tokens? I can see when i am trying to create HEC inputs, it is asking me to select sourcetype where i can only select one sourcetype.

Please help me with this situation.

 

Thanks

Labels (2)
0 Karma
1 Solution

Roy_9
Motivator

Upon validating with Support, I got to know if we want to use the same token for 3 sourcetypes, i was asked to add the sourcetype info manually at the source itself while pushing the payload to Splunk.

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It depends on the source and the endpoint you're using.

If your source can only write raw events to the services/collector/raw, you have no additional metadata so you need three separate tokens - one for each sourcetype. However, if your source can write a proper json request to services/collector/event, you can provide sourcetype as a field in your request. Then the HEC-associated sourcetype works as a default assignment if one is not provided with the event. I don't remember if you don't have to provide allowed sourcetypes anyway.

Roy_9
Motivator

Yes the source will send the events at services/collector/event, Since i can only select one sourcetype, i decided to create 3 different tokens for 3 sourcetypes which are tied to same index.I hope this will be easy to handle.

Thanks so much for your insight.

0 Karma

Roy_9
Motivator

Upon validating with Support, I got to know if we want to use the same token for 3 sourcetypes, i was asked to add the sourcetype info manually at the source itself while pushing the payload to Splunk.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...