Hi @mariamms , here you can find all the information you need about HEC: at first https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf (page 28) https://docs.splunk.com/...
See more...
Hi @mariamms , here you can find all the information you need about HEC: at first https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf (page 28) https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/Data/ShareHECData https://www.youtube.com/watch?v=qROXrFGqWAU In few words, you have to creare an HEC received creating a token that must be passed to the sender. You can also have an intermediate Load Balancer for HA features, in this case, you must have the same token in all the receivers. About Console, what do you mean? HEC hasn't any console. If your're speaking of the Cluster consoles, you have to search for Cluster Master (for Indexer Cluster) and SH Deployer (for Search Head Cluster). You can find information at https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Aboutclusters and https://docs.splunk.com/Documentation/Splunk/9.2.0/DistSearch/AboutSHC At least there's also a Monitorig Console and you can find information at https://docs.splunk.com/Documentation/Splunk/9.2.0/DMC/DMCoverview Ciao. Giuseppe