<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why are AWX and HEC not working? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-AWX-and-HEC-not-working/m-p/636196#M108817</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Newish to splunk here.&lt;/P&gt;
&lt;P&gt;We have an AWX instance (free Tower) and we are trying to send the logs to splunk using this link:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A title="ansible-logs-splunk" href="https://www.redhat.com/sysadmin/ansible-logs-splunk" target="_blank" rel="noopener"&gt;ansible-logs-splunk&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All is good there.&amp;nbsp; I can do a tcpdump and see data going out to port 8088 on my splunk management server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I used this link to set up HEC on Splunk Enterprise 9.0.2:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A title="HEC" href="https://docs.splunk.com/Documentation/Splunk/9.0.2/Data/UsetheHTTPEventCollector" target="_blank" rel="noopener"&gt;HEC&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I can run the curl -k ..... test and get:&amp;nbsp; RETURNS: {"text":"Success","code":0}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;So things seem ok.&amp;nbsp; When I try a search, I get nothing.&amp;nbsp; We've using the default index.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Aaron&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 01:04:15 GMT</pubDate>
    <dc:creator>aaron_francis</dc:creator>
    <dc:date>2023-03-28T01:04:15Z</dc:date>
    <item>
      <title>Why are AWX and HEC not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-AWX-and-HEC-not-working/m-p/636196#M108817</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Newish to splunk here.&lt;/P&gt;
&lt;P&gt;We have an AWX instance (free Tower) and we are trying to send the logs to splunk using this link:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A title="ansible-logs-splunk" href="https://www.redhat.com/sysadmin/ansible-logs-splunk" target="_blank" rel="noopener"&gt;ansible-logs-splunk&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All is good there.&amp;nbsp; I can do a tcpdump and see data going out to port 8088 on my splunk management server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I used this link to set up HEC on Splunk Enterprise 9.0.2:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A title="HEC" href="https://docs.splunk.com/Documentation/Splunk/9.0.2/Data/UsetheHTTPEventCollector" target="_blank" rel="noopener"&gt;HEC&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I can run the curl -k ..... test and get:&amp;nbsp; RETURNS: {"text":"Success","code":0}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;So things seem ok.&amp;nbsp; When I try a search, I get nothing.&amp;nbsp; We've using the default index.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Aaron&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 01:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-AWX-and-HEC-not-working/m-p/636196#M108817</guid>
      <dc:creator>aaron_francis</dc:creator>
      <dc:date>2023-03-28T01:04:15Z</dc:date>
    </item>
  </channel>
</rss>

