Hi All,
Need a quick help on the below issue.
I doubt the issue might be with Token that was created earlier. Do I need to recreate the HTTP token and reconfigure it.
Awaiting for your help.
regards,
Santosh
@santosh_hb,
Yes, each token has a unique value, which is a 128-bit number that is represented as a 32-character globally unique identifier (GUID). You have to create new token after enabling HEC as described in Configure HTTP Event Collector on Splunk Enterprise in the new installation.
@santosh_hb,
Check below configuration if all looks good then re-create the token and use that. (As you have changed Splunk version re-creation of token is probably require)
Hope this helps!!!