Getting Data In

uberAgent

KenPaul
New Member

We looking into uberAgent to be installed on over 17000 endpoints. I'm wanting to know how many HF's would be needed to that many endpoints? Is it volume, number of connections, or both that need to be considered?

Thank you for any feedback given.

Labels (1)
0 Karma

ddrillic
Ultra Champion

From AI - To configure Splunk and uberAgent, first install the Splunk apps on your Splunk server by uploading the files from the uberAgent download. Then, enable the HTTP Event Collector (HEC) in Splunk's global settings to allow uberAgent to send data to it.

Apparently, the uberAgent works with HEC and then you can send the data stream straight to the indexers, does it make sense?

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...