Configure the HTTP Event Collector
z/OS SMF data is sent to Splunk via the HTTP Event Collector (HEC). A token is used to authorize EasySMF to send data to Splunk.
Configure the HEC in Splunk. Go to Settings -> Data Inputs -> HTTP Event Collector
-
Select New Token
-
Give the token a name, e.g. "easysmf_zos".
-
Next>, configure Input Settings. Select Allowed Indexes
-
add the EasySMF indexes listed above. Select easysmf_status as the Default Index.
Review>
Input Type ....................... Token
Name ............................. easysmf_zos
Source name override ............. N/A
Description ...................... N/A
Enable indexer acknowledgements .. No
Output Group ..................... N/A
Allowed indexes .................. easysmf_metrics
easysmf_status
easysmf_job_events
easysmf_dataset_events
easysmf_rmf_metrics
easysmf_tcpip_events
easysmf_zos_events
easysmf_zos_metrics
Default index .................... easysmf_status
Source Type ...................... Automatic
App Context ...................... launcher
Submit>
The token value can be found later on the Data Inputs > HTTP Event Collector settings page.
HTTP Event Collector Global Settings
Open the Global Settings option from the Data Inputs > HTTP Event Collector settings page. The Global Settings page shows you the HEC port and whether SSL (TLS) is enabled.
Make sure the token is enabled.
Configure EasySMF Events
Use the token value from HEC configuration in the splunk_auth configuration parameter or the splunk_hec_token in the CREDENTIALS_DIRECTORY.