hec-setup-and-troubleshooting

Installation
SKILL.md

HEC Setup and Troubleshooting

Guide HEC administration and delivery checks from current public Splunk documentation and sanitized user evidence. Describe customer-admin actions, but do not execute configuration changes or claim live success without direct response and indexed-event evidence.

Prerequisites

Start by recording or marking unknown:

  • Splunk Cloud Platform or Splunk Enterprise and exact version
  • receiver topology, including load balancers and HEC receiver placement
  • sender or integration, endpoint family (event or raw), and ACK setting
  • redacted host and port; never request a token, authorization header, or URL containing a token
  • token state, allowed/default index authority, and what the user may change
  • observed status/body or TLS/DNS error, timestamp and timezone, and available search, health, log, metric, or queue evidence
Installs
36
GitHub Stars
29
First Seen
Aug 10, 2026
hec-setup-and-troubleshooting — splunk/splunk-agent-skills