Hello,
Is it possible to create HEC Token from the CLI of Linux host? Any recommendations how to create HEC token from CLI would be greatly appreciated. Thank you!
Below is how an inputs.conf would look like.
[http://adt]
disabled = false
sourcetype =adt:audit
token = 977xx0B5-E5xx-4xx1-A894-B5DA75XX3A31
indexes =adt_audit
index =adt_audit
For creating a token you can use token generator tools like thishttps://www.uuidgenerator.net/
- Each token has a unique value, which is a 128-bit number that is represented as a 32-character globally unique identifier (GUID). Agents and clients use a token to authenticate their connections to HEC.
Another way is can create something from web via data inputs >http> and it get saved on the etc/apps/splunk_http_input/local/inputs.conf to see what it looks like.
Hope this helps, please upvote or solved if this solution is helpful.
Please use this doc to create HEC via CLI: https://docs.splunk.com/Documentation/Splunk/latest/Data/UseHECfromtheCLI
Or you can directly create inputs.conf as mentioned here.
Please UpVote if helpful.
Hello @sainag_splunk
Those docs are very resourceful, thank you so much.
However, I need to provide HEC token to the data source owner to send log from their server. How can I create that token directly by using inputs.conf file? Would it be possible for you to provide any example/sample inputs.conf file for it
My index =adt_audit and sourcetype=adt:audit
Below is how an inputs.conf would look like.
[http://adt]
disabled = false
sourcetype =adt:audit
token = 977xx0B5-E5xx-4xx1-A894-B5DA75XX3A31
indexes =adt_audit
index =adt_audit
For creating a token you can use token generator tools like thishttps://www.uuidgenerator.net/
- Each token has a unique value, which is a 128-bit number that is represented as a 32-character globally unique identifier (GUID). Agents and clients use a token to authenticate their connections to HEC.
Another way is can create something from web via data inputs >http> and it get saved on the etc/apps/splunk_http_input/local/inputs.conf to see what it looks like.
Hope this helps, please upvote or solved if this solution is helpful.