Monitoring Splunk

Connect HEC token to Monitoring Console

wpb162
Explorer

We get data in using HEC tokens, and the data is flowing just fine. But when we try to view the HTTP Event Collector panel under Indexing > Inputs, it says we have no tokens configured. How do we configure the MC to see the existing tokens?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I believe the tokens must be defined on the MC.  You should be able to do that by copying inputs.conf from a Search Head to the MC and restarting the MC.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...