I am trying to set up HEC for my indexer cluster (v8.0.7), with 2 indexers (and 3 search heads) managed by a master node.
I read multiple docs and articles already, but I want to make sure I get some basic ideas correct first.
In a non-clustered env, it's simple and each HEC client will talk to port 8088 of one indexer.
But in an indexer cluster environment:
Hi @patng_nw
Following link having answers to your first two bullet points, go to very end of post How to deploy HEC and token to indexers in a clust... - Splunk Community
---
An upvote would be appreciated and Accept solution if this reply helps!
That's clear now. I hope Splunk can update their doc to at least give us a high level picture.
@patng_nw link Components that help to manage your deployment - Splunk Documentation having some info but not at HEC level. Set up and use HTTP Event Collector in Splunk Web - Splunk Documentation further reading.
Same you can use DS as well push to indexers, if you have HF in distributed set-up that's one of the place HEC can be enabled. It all depends how huge the load is on indexers.
Thanks for the links. I have read them before I post this question here, as they don't provide a clear high-level picture which list out the options we have.
Hi @patng_nw
Following link having answers to your first two bullet points, go to very end of post How to deploy HEC and token to indexers in a clust... - Splunk Community
---
An upvote would be appreciated and Accept solution if this reply helps!