From 706a0bea7894eaa7289def73f28e7fa0989f1fb9 Mon Sep 17 00:00:00 2001 From: mstopa-splunk <139441697+mstopa-splunk@users.noreply.github.com> Date: Thu, 25 Jan 2024 10:44:29 +0100 Subject: [PATCH] docs: update Splunk setup section (#2324) --- docs/gettingstarted/getting-started-splunk-setup.md | 8 +------- 1 file changed, 1 insertion(+), 7 deletions(-) diff --git a/docs/gettingstarted/getting-started-splunk-setup.md b/docs/gettingstarted/getting-started-splunk-setup.md index 27d4fc21fa..57d4730a33 100644 --- a/docs/gettingstarted/getting-started-splunk-setup.md +++ b/docs/gettingstarted/getting-started-splunk-setup.md @@ -24,13 +24,7 @@ using the SC4S defaults. SC4S can be easily customized to use different indexes * print * _metrics (Optional opt-in for SC4S operational metrics; ensure this is created as a metrics index) -#### Install Related Splunk Apps - -Install the following: - -* [IT Essentials Work](https://splunkbase.splunk.com/app/5403/) - -#### Configure the Splunk HTTP Event Collector +## Configure the Splunk HTTP Event Collector - Set up the Splunk HTTP Event Collector with the HEC endpoints behind a load balancer (VIP) configured for https round robin *WITHOUT* sticky session. Alternatively, a list of HEC endpoint URLs can be configured in SC4S (native syslog-ng load balancing) if no load balancer is in