The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling an HTTP Event Collector token service on a Splunk Enterprise Server

Prev Next

After you create an HTTP Event Collection (HEC) token, you must enable the token to connect and run the Layer 7 Metadata Event Exporter feature on your Network Security appliance.

Prerequisites

To enable the Splunk HEC Token:
  1. Log in to the Splunk Enterprise server using the Web UI.

  2. Click Settings > Data Inputs.

    The HTTP Event Collector page appears.

  3. Click Global Settings.

    NX_SplunkEnableToken_scap.png

    Select the global settings as indicated in the following table.

    Note

    The default index, default output group fields are optional

    Field

    Input

    All Tokens

    Enabled

    Default Source Type

    json_no_timestamp

    Default index (optional)

    By default, all events are stored in the main index. You can specify a different index by using: index = "<index_name>".

    Default Output Group (optional)

    Default is none. You can specify an output group to forward data.

    Use Deployment Server

    Default is unchecked, when your Splunk Enterprise server is a deployment client and receives events from the Network Security appliance. Check if your Splunk Enterprise server acts as a centralized configuration manager and sends updates to deployment clients.

    Enable SSL

    Select Enable SSL to have HEC listen and communicate over HTTPS rather than HTTP.

    HTTP Port Number

    Use the default HTTP port number or enter a custom HTTP port number to run HEC on a different port.

  4. Click Save.