Getting Data In

Is it possible to rename a HEC under Data Inputs » HTTP Event Collector ?

mark-jones
Explorer

Does anyone know if it's possible to rename an HEC or do you have to create a new one and update the token everywhere?  Seems like just renaming it should be an option under edit, but not seeing anything.

Thanks,

 

markjones_0-1663689574578.png

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have access to the CLI, you should be able to change the name by editing the appropriate inputs.conf file.  Then restart Splunk or push the bundle.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

And if/when you have several nodes after HEC LB VIP then you must do this on all nodes (HF or/and indexers).

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...