I used Azure/Splunk Enterprise deployment to set up Splunk on my Azure instance.
I then did this:
I get:
{"text":"Invalid token","code":4}
Based on what I was reading, I need to push the change out to the Indexers.
So here's my questions:
Thanks for helping a newbie!
When you set up HEC on the search head, Splunk added a stanza to inputs.conf for you. Copy that stanza to indexes.conf in an app and install that app on your indexers (use the Cluster Manager if you have one). All indexers should then have the same HEC settings.
When you set up HEC on the search head, Splunk added a stanza to inputs.conf for you. Copy that stanza to indexes.conf in an app and install that app on your indexers (use the Cluster Manager if you have one). All indexers should then have the same HEC settings.