Deployment Architecture

Enable Deployment and HEC tokens in Global settings

SecurityFeller
Explorer

We are generating HEC tokens on a deployment server and pushing them out to the HECs. 

HEC tokens are disabled by default on the HECs and the deployment server and need to be enabled in global settings. 

What I've done so far is:

-authorize.conf, this is for user tokens and isn't working for HEC tokens

-the CLI command for token enable isn't working because it's not enabled globally

-inputs.conf has [http] disabled=0

 

The only thing that has worked is enabling it via the UI. Is there a way to enable these over CLI?

0 Karma
1 Solution

SecurityFeller
Explorer

Solved. Splunk did not take conf file enablement on creation. It must be modified afterwards. 

View solution in original post

SecurityFeller
Explorer

Solved. Splunk did not take conf file enablement on creation. It must be modified afterwards. 

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...