Hello All,
I am installing Alert manager Enterprise on a standalone on-prem server. I can it indexed in a existing index or should I be using another new index for config.
Also what would be the HEC host field, will it be my url for the splunk instance and what would be the HEC port as well.
In my understanding is that, alert manager takes splunk alerts and displays it, Im not sure why HEC is even used when setting this up?
Thank you for all the help! #