<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk HEC http request not working in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700099#M20319</link>
    <description>&lt;P&gt;Please don't every disable SSL for HTTP Event Collection - this is purely from a security stand point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you absolutely must have an HTTP only connection please setup a separate HF for this purpose.&amp;nbsp; Never expose your indexing tier to non-SSL connections.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2024 15:06:34 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-09-25T15:06:34Z</dc:date>
    <item>
      <title>Splunk HEC http request not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700052#M20312</link>
      <description>&lt;P&gt;Splunk HEC was configured as defined in the documentation. I could see that I can send data using https URL. When sending same data using HTTP URL - request is failing with the error "curl: (56) Recv failure: Connection reset by peer".&lt;/P&gt;&lt;P&gt;curl &lt;A href="https://community.splunk.com/" target="_blank"&gt;https://&amp;lt;host&amp;gt;:&amp;lt;port&amp;gt;/services/collector&lt;/A&gt;&amp;nbsp;-H&amp;nbsp; 'Authorisation: Splunk &amp;lt;token&amp;gt;' -d '{"sourcetype": "demo", "event": "Test data!"}'&lt;/P&gt;&lt;P&gt;OUTPUT/Response :&amp;nbsp; {"text":"Success","code":0}&lt;/P&gt;&lt;P&gt;curl &lt;A href="https://community.splunk.com/" target="_blank"&gt;http://&amp;lt;host&amp;gt;:&amp;lt;port&amp;gt;/services/collector&lt;/A&gt;&amp;nbsp;-H&amp;nbsp; 'Authorisation: Splunk &amp;lt;token&amp;gt;' -d '{"sourcetype": "demo", "event": "Test data!"}'&lt;/P&gt;&lt;P&gt;curl: (56) Recv failure: Connection reset by peer&lt;/P&gt;&lt;P&gt;This was the command used to enable token /opt/splunk/bin/splunk http-event-collector enable -name &amp;lt;hec_name&amp;gt; -uri &lt;A href="https://localhost:8089" target="_blank"&gt;https://localhost:8089&lt;/A&gt;&lt;BR /&gt;which worked perfectly fine&lt;/P&gt;&lt;P&gt;thought I had to enable http URL and executed below command:&lt;/P&gt;&lt;P&gt;/opt/splunk/bin/splunk http-event-collector enable -name catania-app-stat -uri &lt;A href="http://localhost:8089" target="_blank"&gt;http://localhost:8089&lt;/A&gt;&lt;BR /&gt;Error/Output : Cannot connect Splunk server&lt;/P&gt;&lt;P&gt;What am I missing here. How do I get source to send data over HTTP protocol.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 07:02:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700052#M20312</guid>
      <dc:creator>sdkp03</dc:creator>
      <dc:date>2024-09-25T07:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC http request not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700064#M20314</link>
      <description>&lt;P&gt;By default HEC is running on HTTPS. If you really want to disable SSL then you can change it by doing the below&amp;nbsp;&lt;/P&gt;&lt;P&gt;- In Splunk UI Goto -&amp;gt; Settings -&amp;gt;&amp;nbsp;Data Inputs -&amp;gt; HTTP Event Collector&lt;/P&gt;&lt;P&gt;- Click on "Global Settings" Button and &lt;STRONG&gt;uncheck&lt;/STRONG&gt; the "Enable SSL" Option&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jawahir007_0-1727251816326.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32803i018241C3236715BA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jawahir007_0-1727251816326.png" alt="jawahir007_0-1727251816326.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;------&lt;/P&gt;&lt;H5&gt;&lt;STRONG&gt;If you find this solution helpful, please consider accepting it and awarding karma points !!&lt;/STRONG&gt;&lt;/H5&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 15:40:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700064#M20314</guid>
      <dc:creator>Jawahir</dc:creator>
      <dc:date>2024-09-25T15:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC http request not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700099#M20319</link>
      <description>&lt;P&gt;Please don't every disable SSL for HTTP Event Collection - this is purely from a security stand point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you absolutely must have an HTTP only connection please setup a separate HF for this purpose.&amp;nbsp; Never expose your indexing tier to non-SSL connections.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 15:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700099#M20319</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-09-25T15:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC http request not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700149#M20320</link>
      <description>&lt;P&gt;So this is a global setting and I cannot choose protocol per token is it?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 23:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700149#M20320</guid>
      <dc:creator>sdkp03</dc:creator>
      <dc:date>2024-09-25T23:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC http request not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700151#M20321</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194981"&gt;@dural_yyz&lt;/a&gt;&amp;nbsp;. I was thinking of a solution where for a specific token I could enable HTTP protocol. I infer based on your comment and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135068"&gt;@Jawahir&lt;/a&gt;&amp;nbsp;comment, I infer that its a global setting and cannot be changed for a specific token. I wonder why Splunk recommends to use HTTP for performance optimisation(referring to below statement from listed ref link).&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sending data over HTTP results in a significant performance improvement compared to sending data over HTTPS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/TroubleshootHTTPEventCollector?_gl=1*1nghc0j*_gcl_au*Nzg1MzY5MzUwLjE3MjQxOTk4MzQ.*FPAU*Nzg1MzY5MzUwLjE3MjQxOTk4MzQ.*_ga*MTU5MjI4NDE4MS4xNjYyMDk1ODgw*_ga_5EPM2P39FV*MTcyNjc5NjM2NS42NzguMS4xNzI2Nzk2MzY5LjAuMC44MTIxODU0Njk.*_fplc*QjJOT1NjUFJSViUyRnJ5ZFprQUJIOHRsZUx1dk9WZDFKaUFXQW52OGQwYUkwOVh0WGslMkYyY3BGbnJDUDVZWSUyQkY0VE1JekY3VWdLdEd3SVhrU1QyVDFPNFNEUiUyRlZwa1pkaU54R2J0dDV2Y3JQcGVjVFRMd05Na0JjSTdoVHdZN0ElM0QlM0Q." target="_blank"&gt;Troubleshoot HTTP Event Collector - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 23:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700151#M20321</guid>
      <dc:creator>sdkp03</dc:creator>
      <dc:date>2024-09-25T23:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC http request not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700177#M20323</link>
      <description>&lt;P&gt;Think layers. HTTP vs. HTTPS is something that happens before even any HTTP request is being sent so it's enabled on a whole network port level and all HEC tokens are serviced by either HTTP or HTTPS input.&lt;/P&gt;&lt;P&gt;Whether HTTP/HTTPS issue is important for you security-wise depends on your approach to the data you're ingesting - is it highly confidential and anyone eavesdropping into it on the wire is a great concern to you or not.&lt;/P&gt;&lt;P&gt;While Splunk states that switching from HTTPS to HTTP can give a significant performance boost I'd be cautious with such general statements. It does depend on the hardware you're using and the volume of data you're processing. If you have a fairly modern server or a properly specced VM and you're not processing some humongous amounts of data you should be fairly ok with HTTPS enabled.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 09:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700177#M20323</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-26T09:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC http request not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700225#M20327</link>
      <description>&lt;P&gt;My background is network engineering so I can't speak to any specific software processing benefits of HTTP vs HTTPS.&amp;nbsp; However, since HTTP is essentially plain text that would be fairly simple to take the packet off the wire.&amp;nbsp; Having to decrypt HTTPS would by the very nature of an additional step add processing requirements but as pointed out by others depending upon the compute power of your server(s) there usually isn't a noticeable hit or queuing of data.&amp;nbsp; Most systems today have compute that will outperform the physical network connection.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 14:02:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-HEC-http-request-not-working/m-p/700225#M20327</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-09-26T14:02:20Z</dc:date>
    </item>
  </channel>
</rss>

