Skip to main content
Skip table of contents

Create an HTTP Event Collector (HEC)

For establishing a connection between the SAP system and Splunk an HTTP Event Collector (HEC) must be created within Splunk. In order to create the HEC…

  • Click on “Settings”, then on “Data Inputs”.

  • Create a new HTTP Event Collector by clicking on “+ Add new”.

  • Provide a valid and reasonable name identifying the HEC.

  • Leave all other settings in default values and press “Next”.

  • Choose the indexes you created here as an input source. Please create separate HEC endpoints for metrics and events indexes.

  • Verify settings and click “Submit” to create the new HEC configuration.

  • Note the value of the token that has been created. It will be needed when configuring the SAP add-on.

  • Verify that the HEC configuration is enabled.

  • If you have different staff for administering Splunk and SAP Basis, hand-over the following values to the SAP Basis team or your service provider:

Parameter

Value

Comment

HEC Index Name

sap (or custom)

HEC Token

<value>

Token value as mentioned above.

HEC Endpoint URL

http://<Splunk Hostname>

for a non-SSL setup.

HEC Enpoint URL SSL

https://<Splunk Hostname>

for an SSL setup.

TCP Port

8088 (Splunk Enterprise default)

443 (Splunk Cloud default)

If a different port is configured, please use this one.

SSL Certificate

corresponding *.CER-file

Only if an SSL setup is intended.

If you use an SSL encrypted connection, follow these steps for configuring SSL. Continue to create a role for accessing the SAP data indexes.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.