Preparing Splunk
To use Splunk, you need to set up HTTP Event Collector (HEC). To do this, follow the steps below:
-
Open Splunk.
-
Go to Settings > Data inputs.

-
Click HTTP Event Collector.
-
Click the green New Token button from the top-right corner.
-
Fill in the Name field with a name for your HEC.
-
Click Next.

-
Select the index you want to ingest data into. In the example screenshot main is selected. You can customize your choice in this page.

-
Click Review.
-
Click Submit.