All Apps and Add-ons

Splunk MINT: How can i set up duplicated HTTP Event Collector server? (Active - Active)

sky9214
Engager

I want to send the Splunk MINT event log to each Http Event Collector?

Is there a way to set up two tokens on SDK?

0 Karma

croyal_splunk
Splunk Employee
Splunk Employee

You cannot set up 2 tokens on the same project integrated with a MINT SDK. This will not work.

0 Karma

gjanders
SplunkTrust
SplunkTrust

Your question appears to be slightly confusing, you refer to a duplicated HTTP event collector server, however the HTTP event collector is just another Splunk input, therefore the only way to run an active/active scenario would be 2 universal forwarders or 2 heavy forwarders. It would not make sense to run multiple http event collector ports on the same instance of Splunk.

The latter part of your question mentions two tokens on the SDK, I assume your again referring to the HTTP event collector ? You would use the same token on 2 forwarders if you were doing active/active, and then you would add additional tokens if required.

The inputs.conf documentation is here refer to the http event collector section. Or refer to the http event collector documentation

You will need something to load balance between the 2 servers, I use a load balancer server to distribute traffic to 2 heavy forwarders, however you could also do this using universal forwarders as per this Splunk blog post comparing heavy vs universal forwarders.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...