Skip to main content

Configure the HTTP Event Collector

z/OS SMF data is sent to Splunk via the HTTP Event Collector (HEC). A token is used to authorize EasySMF to send data to Splunk.

Configure the HEC in Splunk. Go to Settings -> Data Inputs -> HTTP Event Collector

  • Select New Token

  • Give the token a name, e.g. "easysmf_zos".

  • Next>, configure Input Settings. Select Allowed Indexes

  • add the EasySMF indexes listed above. Select easysmf_status as the Default Index.

Review>

Input Type ....................... Token
Name ............................. easysmf_zos
Source name override ............. N/A
Description ...................... N/A
Enable indexer acknowledgements .. No
Output Group ..................... N/A
Allowed indexes .................. easysmf_metrics
easysmf_status
easysmf_job_events
easysmf_dataset_events
easysmf_rmf_metrics
easysmf_tcpip_events
easysmf_zos_events
easysmf_zos_metrics
Default index .................... easysmf_status
Source Type ...................... Automatic
App Context ...................... launcher

Submit>

The token value can be found later on the Data Inputs > HTTP Event Collector settings page.

HTTP Event Collector Global Settings

Open the Global Settings option from the Data Inputs > HTTP Event Collector settings page. The Global Settings page shows you the HEC port and whether SSL (TLS) is enabled.

Make sure the token is enabled.

Configure EasySMF Events

Use the token value from HEC configuration in the splunk_auth configuration parameter or the splunk_hec_token in the CREDENTIALS_DIRECTORY.