Getting Data In

forwarding baked HEC traffic between two Splunk Entreprise Instances

Brainizer
Engager

Hello,

I would like to forward data between two splunk instances in clear text. For that I use HEC. This is my outputs.conf . 

 

[httpout]
httpEventCollectorToken = <HEC_TOKEN>
uri = http://hec_target:8088

 

I would like to inspect the events with a third party application, but they appear to be encoded in s2s. Also this configuration sends the events to the /services/collector/s2s endpoint, which is not the same one would forward clear text (JSON) events to. Is there any way to send the events in a readable format?

I am aware there is syslog output. I would try it if there is no possibility to change the HEC output accordingly. 

Thanks in advance.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...