Hi All,
Need a quick help on the below issue.
I doubt the issue might be with Token that was created earlier. Do I need to recreate the HTTP token and reconfigure it.
Awaiting for your help.
Yes, each token has a unique value, which is a 128-bit number that is represented as a 32-character globally unique identifier (GUID). You have to create new token after enabling HEC as described in Configure HTTP Event Collector on Splunk Enterprise in the new installation.
Check below configuration if all looks good then re-create the token and use that. (As you have changed Splunk version re-creation of token is probably require)
Hope this helps!!!