<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTP Event Collector URL in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538000#M490</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using the free cloud trial, and none of the URLs suggested within the &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/UsetheHTTPEventCollector" target="_self"&gt;documentation&lt;/A&gt; work.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[HOST]/services/collector&lt;/FONT&gt; throws a 303 error, redirecting to &lt;FONT face="courier new,courier"&gt;[HOST]/en-GB/services/collector&lt;/FONT&gt; which in turn throws a 404 error.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;input-[HOST], inputs-[HOST], http-inputs-[HOST] do not resolve.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;inputs.[HOST]&lt;/FONT&gt; resolves, but throws an SSL error as the wildcard cert attached to it does not cover the extra tier in the FQDN.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[HOST]:8088&lt;/FONT&gt; resolves, but throws an SSL error as the cert attached to it does not match the FQDN (&lt;SPAN class="info"&gt;SplunkServerDefaultCert&lt;/SPAN&gt;).&lt;BR /&gt;&lt;BR /&gt;Any idea what I should be using?&lt;BR /&gt;&lt;BR /&gt;TIA,&lt;BR /&gt;Martin...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 31 Jan 2021 12:23:30 GMT</pubDate>
    <dc:creator>hnfd73hd8sjhDD</dc:creator>
    <dc:date>2021-01-31T12:23:30Z</dc:date>
    <item>
      <title>HTTP Event Collector URL</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538000#M490</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using the free cloud trial, and none of the URLs suggested within the &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/UsetheHTTPEventCollector" target="_self"&gt;documentation&lt;/A&gt; work.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[HOST]/services/collector&lt;/FONT&gt; throws a 303 error, redirecting to &lt;FONT face="courier new,courier"&gt;[HOST]/en-GB/services/collector&lt;/FONT&gt; which in turn throws a 404 error.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;input-[HOST], inputs-[HOST], http-inputs-[HOST] do not resolve.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;inputs.[HOST]&lt;/FONT&gt; resolves, but throws an SSL error as the wildcard cert attached to it does not cover the extra tier in the FQDN.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[HOST]:8088&lt;/FONT&gt; resolves, but throws an SSL error as the cert attached to it does not match the FQDN (&lt;SPAN class="info"&gt;SplunkServerDefaultCert&lt;/SPAN&gt;).&lt;BR /&gt;&lt;BR /&gt;Any idea what I should be using?&lt;BR /&gt;&lt;BR /&gt;TIA,&lt;BR /&gt;Martin...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 12:23:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538000#M490</guid>
      <dc:creator>hnfd73hd8sjhDD</dc:creator>
      <dc:date>2021-01-31T12:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector URL</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538210#M491</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231053"&gt;@hnfd73hd8sjhDD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;According to documentation our should use below URL; (you should replace stackname with yours)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;https://stackname.splunkcloud.com:8088/services/collector/event&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 04:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538210#M491</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-02T04:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector URL</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538225#M492</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;P&gt;As noted: using that URI throws an SSL error as the certificate doesn't match (the cert returned is a default one, not the one for the stack).&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;Martin...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 07:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538225#M492</guid>
      <dc:creator>hnfd73hd8sjhDD</dc:creator>
      <dc:date>2021-02-02T07:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector URL</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538230#M493</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231053"&gt;@hnfd73hd8sjhDD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I believe Splunk Free Cloud Trail uses self sign certificate. That is why you may need to disable certificate check on your tests.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 07:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538230#M493</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-02T07:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector URL</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538263#M494</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Is that a definite (have you tried it yourself?)&lt;/P&gt;&lt;P&gt;The problem is that the library I'm using doesn't have the ability to disable SSL validation (it's an intentional choice: if it isn't there as an option, someone can't accidentally make a mistake and push it to a live environment).&lt;/P&gt;&lt;P&gt;If that is the case, then the documentation definitely needs cleaning up, and a note added to this effect (apart from there being contradicting examples in ther same document about which URI to use). &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Martin...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 11:13:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538263#M494</guid>
      <dc:creator>hnfd73hd8sjhDD</dc:creator>
      <dc:date>2021-02-02T11:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector URL</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538271#M495</link>
      <description>&lt;P&gt;As far as I know it is self signed for free trial. But this is not a new info.&lt;/P&gt;&lt;P&gt;You can confirm with Splunk support.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 12:17:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538271#M495</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-02T12:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector URL</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538272#M496</link>
      <description>&lt;P&gt;I've just tried using curl (with verification off) and it works ok (event ends up in the right place).&lt;/P&gt;&lt;P&gt;(thanks for your help).&lt;/P&gt;&lt;P&gt;Seems like a potential bin-fire in the waiting for anyone evaluating Splunk though. Someone now has to remember to re-enable TLS validation if they move from free to cloud/enterprise, otherwise their sensitive log data is accessible by anyone along the network path who wants to MITM the connection.&lt;/P&gt;&lt;P&gt;Martin...&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 12:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/HTTP-Event-Collector-URL/m-p/538272#M496</guid>
      <dc:creator>hnfd73hd8sjhDD</dc:creator>
      <dc:date>2021-02-02T12:20:18Z</dc:date>
    </item>
  </channel>
</rss>

