The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Creating an HTTP Event Collector Token on a Splunk Enterprise Server

Prev Next

Log into the Splunk Enterprise server using the Web UI and create an HTTP Event Collection (HEC) token to connect and run the Layer 7 Metadata Event Exporter feature on your ADD Product Series appliance.

An HEC token is a 32-bit number that allows a logging connection between agents and HTTP clients, such as the ADD Product Series appliance and Splunk Enterprise. After the token is presented and accepted, events can be delivered by your ADD Product Series appliance in JSON format to the Splunk Enterprise server.

Note

You disable per-token acknowledgments by clearing the Enable indexer acknowledgement checkbox.

Prerequisites

  • Administrator or Operator access to the ADD Product Series appliance.

  • An active subscription to the Splunk Enterprise server.

  • A connection to the Splunk Enterprise server.

To create the Splunk HEC Token:
  1. Log into the Splunk Enterprise server Web UI.

  2. Click Settings > Data Inputs.

    The HTTP Event Collector page appears.

  3. Click New Token.

    NX_SplunkCreateToken_scap.png

    The Add Data page appears.

  4. Click Next to configure a new token for receiving data over HTTP.

    NX_SplunkConfigureToken_scap.png

    Enter the token information as indicated in the following table.

    Field

    Description

    Name

    A name for the HEC input token.

    Source name override

    A name for the event data associated with the HEC token.

    Description (optional)

    A description for the HEC input token.

    Output Group (optional)

    The name of an existing output forwarding group set up by the Splunk administrator.

    Enable indexer acknowledgement

    Clear the checkbox.

  5. Click Next.

  6. Click Select and then select Structured from the Select Source Type pull-down menu to format and categorize your data.

  7. Choose json_no_timestamp format for event data.

  8. Click Review to verify your HEC token input settings.

  9. Click Submit to confirm settings.

  10. Copy and save the token value for your reference.