First we'll enable the HEC. As we noted in the preceding section, by default, the HEC is not enabled upon initial installation of Splunk. To enable the HEC in your local Splunk instance, perform the following steps, after which you can refer to the screenshot:
- Go to Settings | Data Inputs
- Click on HTTP Event Collector
- Click on the Global Settings button in the upper-right corner of the page
- Select Enabled for All Tokens
- Leave Enable SSL checked, as it should be checked by default
- Leave the rest at the default settings so your window appears as shown here, and click on Save:
