<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event collector in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600909#M1483</link>
    <description>&lt;P&gt;Ok&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246351"&gt;@danylan&lt;/a&gt;&amp;nbsp;got it, i remember there will be slight change in url for self service and managed service cloud, please have a look at the documentation.&lt;/P&gt;&lt;P&gt;Not sure about the below error, may be you need to open a fw connection from your machine to&amp;nbsp;&lt;A href="https://http-inputs-hostname.splunkcloud.com" target="_blank"&gt;https://http-inputs-hostname.splunkcloud.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If it is resolved, please accept the solution and appreciate you giving karma point.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2022 16:12:56 GMT</pubDate>
    <dc:creator>Roy_9</dc:creator>
    <dc:date>2022-06-07T16:12:56Z</dc:date>
    <item>
      <title>Event collector: What is the correct format in my search?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600478#M1465</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am following this documentation from GCP [1], which mentions to omit&amp;nbsp;YOUR_SPLUNK_HEC_URL&lt;SPAN&gt;&amp;nbsp;must not include the HEC endpoint path, for example,&amp;nbsp;&lt;/SPAN&gt;/services/collector&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My question is more specifically related to this section [2], it mentions that format should be&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&amp;lt;protocol&amp;gt;://http-inputs.&amp;lt;host&amp;gt;.splunkcloud.com:&amp;lt;port&amp;gt;/&amp;lt;endpoint&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=""&gt;You must add&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;http-inputs-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before the &amp;lt;host&amp;gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;which one would be the correct url, for eg&lt;/P&gt;
&lt;P&gt;&lt;A href="https://http-inputs.xxxx.splunkcloud.com:433" target="_blank" rel="noopener"&gt;https://http-inputs.xxxx.splunkcloud.com:433&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&lt;A href="https://http-inputs.xxxx.splunkcloud.com:433" target="_blank" rel="noopener"&gt;https://http-inputs-xxxx.splunkcloud.com:433&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN class=""&gt;Send data to HTTP Event Collector on Splunk Cloud Platform&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;[1]&lt;A href="https://cloud.google.com/architecture/deploying-production-ready-log-exports-to-splunk-using-dataflow#deploy_the_dataflow_pipeline" target="_blank" rel="noopener"&gt;https://cloud.google.com/architecture/deploying-production-ready-log-exports-to-splunk-using-dataflow#deploy_the_dataflow_pipeline&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;[2]&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector#Configure_HTTP_Event_Collector_on_Splunk_Cloud_Platform" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector#Configure_HTTP_Event_Collector_on_Splunk_Cloud_Platform&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 03:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600478#M1465</guid>
      <dc:creator>danylan</dc:creator>
      <dc:date>2022-06-06T03:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600490#M1466</link>
      <description>&lt;P&gt;I believe it's with hyphen (see "where:" section in&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector#Send_data_to_HTTP_Event_Collector_on_Splunk_Cloud_Platform" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector#Send_data_to_HTTP_Event_Collector_on_Splunk_Cloud_Platform&lt;/A&gt;) where it says "&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;You must add&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;http-inputs-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before the &amp;lt;host&amp;gt;"&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 15:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600490#M1466</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-06-03T15:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600589#M1470</link>
      <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246351"&gt;@danylan&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please use the below format for streaming the logs via HEC.&lt;/P&gt;&lt;P&gt;&lt;A href="https://http-inputs-hostname.splunkcloud.com" target="_blank" rel="noopener"&gt;https://http-inputs-hostname.splunkcloud.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;endpoint name would be&amp;nbsp;services/collector/event or services/collector/raw.&lt;BR /&gt;&lt;BR /&gt;Also the port name would be 443, i guess you made a typo to 433 below.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 15:05:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600589#M1470</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2022-06-05T15:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600689#M1473</link>
      <description>&lt;P&gt;433 was a typo, thanks. After changing with the hyphen it is still complaining about the url formation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Url format should match PROTOCOL://HOST:PORT]&lt;/P&gt;&lt;P&gt;When following the Splunk docs does it matter if we are on Splunk Cloud Platform or Splunk Enterprise? From the docs it seems the format is a bit different.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 13:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600689#M1473</guid>
      <dc:creator>danylan</dc:creator>
      <dc:date>2022-06-06T13:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600719#M1475</link>
      <description>&lt;P&gt;yes the format of the url changes on where you are sending the data either to splunk enterprise or splunk cloud.&lt;/P&gt;&lt;P&gt;Currently I am using splunk cloud and we curl from our sources using the below format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;curl -H "Authorization: Splunk &amp;lt;enter hec token&amp;gt;" &lt;A href="https://urldefense.proofpoint.com/v2/url?u=https-3A__http-2Dinputs-2Dfoxgryphon.splunkcloud.com_services_collector_event&amp;amp;d=DwQGaQ&amp;amp;c=uw6TLu4hwhHdiGJOgwcWD4AjKQx6zvFcGEsbfiY9-EI&amp;amp;r=8unWsyQ1Eg-oxNcf0NcOSn4FRzJQtKuntO-Kqvno4So&amp;amp;m=2GZI4fWUiwUbe7BzL7pX5Z8MyzMJIFiIh1W-OqzFw1OOKlazPoDBQpPoJDkGaTOk&amp;amp;s=Oah1Se11pLFrbhTdxkJffjkWh7BvMmmoFcuHDDkZGns&amp;amp;e=" target="_blank"&gt;https://http-inputs-stackname.splunkcloud.com/services/collector/event&lt;/A&gt; -d '{"sourcetype": "test", "index": "test", "event": {"message": "Hello world!"}}'&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 15:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600719#M1475</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2022-06-06T15:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600721#M1476</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224632"&gt;@Roy_9&lt;/a&gt;&amp;nbsp;, ty for reply, i appreciate.&lt;/P&gt;&lt;P&gt;I am seeing something different&lt;/P&gt;&lt;P&gt;I am on splunk cloud not on enterprise my token is&amp;nbsp;&lt;SPAN&gt;e6a0b67b-e6d0-418f-a2cd-4493804c7c92&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I only get a success with the following&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;curl -k -H "Authorization: Splunk &lt;/SPAN&gt;&lt;SPAN&gt;e6a0b67b-e6d0-418f-a2cd-4493804c7c92&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;A href="https://urldefense.proofpoint.com/v2/url?u=https-3A__http-2Dinputs-2Dfoxgryphon.splunkcloud.com_services_collector_event&amp;amp;d=DwQGaQ&amp;amp;c=uw6TLu4hwhHdiGJOgwcWD4AjKQx6zvFcGEsbfiY9-EI&amp;amp;r=8unWsyQ1Eg-oxNcf0NcOSn4FRzJQtKuntO-Kqvno4So&amp;amp;m=2GZI4fWUiwUbe7BzL7pX5Z8MyzMJIFiIh1W-OqzFw1OOKlazPoDBQpPoJDkGaTOk&amp;amp;s=Oah1Se11pLFrbhTdxkJffjkWh7BvMmmoFcuHDDkZGns&amp;amp;e=" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://&lt;/SPAN&gt;&lt;/A&gt;&lt;A href="https://http-inputs.prd-p-gap0o.splunkcloud.com:8888/services/collector/event" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;prd-p-gap0o&lt;/SPAN&gt;&lt;/A&gt;&lt;A href="https://urldefense.proofpoint.com/v2/url?u=https-3A__http-2Dinputs-2Dfoxgryphon.splunkcloud.com_services_collector_event&amp;amp;d=DwQGaQ&amp;amp;c=uw6TLu4hwhHdiGJOgwcWD4AjKQx6zvFcGEsbfiY9-EI&amp;amp;r=8unWsyQ1Eg-oxNcf0NcOSn4FRzJQtKuntO-Kqvno4So&amp;amp;m=2GZI4fWUiwUbe7BzL7pX5Z8MyzMJIFiIh1W-OqzFw1OOKlazPoDBQpPoJDkGaTOk&amp;amp;s=Oah1Se11pLFrbhTdxkJffjkWh7BvMmmoFcuHDDkZGns&amp;amp;e=" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;.splunkcloud.com:8088/services/collector/event&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; -d '{"sourcetype": "test", "index": "test", "event": {"message": "Hello world!"}}'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;#i added -k to allow insecure connection but it does recognize the uri&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When i try with http-inputs- it fails&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note: I am on a trial account by the way.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 16:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600721#M1476</guid>
      <dc:creator>danylan</dc:creator>
      <dc:date>2022-06-06T16:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600909#M1483</link>
      <description>&lt;P&gt;Ok&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246351"&gt;@danylan&lt;/a&gt;&amp;nbsp;got it, i remember there will be slight change in url for self service and managed service cloud, please have a look at the documentation.&lt;/P&gt;&lt;P&gt;Not sure about the below error, may be you need to open a fw connection from your machine to&amp;nbsp;&lt;A href="https://http-inputs-hostname.splunkcloud.com" target="_blank"&gt;https://http-inputs-hostname.splunkcloud.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If it is resolved, please accept the solution and appreciate you giving karma point.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 16:12:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Event-collector-What-is-the-correct-format-in-my-search/m-p/600909#M1483</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2022-06-07T16:12:56Z</dc:date>
    </item>
  </channel>
</rss>

