Getting Data In

How to edit Splunk HEC token value?

kristen
Explorer

I want to configure two HEC tokens as the same because I want to load balance traffic between them. I followed the document - https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UseHECusingconffiles,

 

I edited the /opt/splunk/etc/apps/splunk_httpinput/local/inputs.conf:

1. Create new stanza

- The name of the stanza is the same as the HEC token name that I want to edit
[hec-test1]

2. Under the stanza, specify the new token value for overriding

token = xxxxx

 

 

After the edit, it does not work. The Splunk even return error:

Checking: /opt/splunk/etc/apps/splunk_httpinput/local/inputs.conf
Invalid key in stanza [hec-test1] in /opt/splunk/etc/apps/splunk_httpinput/local/inputs.conf, line 4: token (value: xxxxx).

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

when you have created it in first HEC node with GUI or REST api, then just copy paste that token part from original conf file to second node’s conf file. Then restart second splunkd.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...