hec-setup-and-troubleshooting
Installation
SKILL.md
HEC Setup and Troubleshooting
Guide HEC administration and delivery checks from current public Splunk documentation and sanitized user evidence. Describe customer-admin actions, but do not execute configuration changes or claim live success without direct response and indexed-event evidence.
Prerequisites
Start by recording or marking unknown:
- Splunk Cloud Platform or Splunk Enterprise and exact version
- receiver topology, including load balancers and HEC receiver placement
- sender or integration, endpoint family (
eventorraw), and ACK setting - redacted host and port; never request a token, authorization header, or URL containing a token
- token state, allowed/default index authority, and what the user may change
- observed status/body or TLS/DNS error, timestamp and timezone, and available search, health, log, metric, or queue evidence