<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help Needed: HTTP Event Collector Bearer Token not Recognized in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-Needed-HTTP-Event-Collector-Bearer-Token-not-Recognized/m-p/691807#M115039</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Check Point Skyline - Splunk Configuration Issue: Unable to get Data In&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;Issue Summary: &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Splunk Enterprise Indexer will not accept HTTP Event Collector HEC_Token from Check Point Gateway resulting in no Skyline (Open Telemetry) data being ingested into Splunk.&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;I need help to get splunk indexer to recognise the token and allow data to be ingested.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please note this error was also replicated on different Splunk Instance to determine potential root cause. Could potentially be attributed to the payload-no-tls.json file not being formatted or compiled correctly on the Gateway.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Documentation used to configure set up:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Check Point Skyline Deployment:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178566" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk178566&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Official Check Point Skyline Guide PDF:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Appliances/Skyline/CP_Skyline_AdminGuide.pdf" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Appliances/Skyline/CP_Skyline_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Skyline Troubleshooting and FAQ:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk179870" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk179870&lt;/A&gt;&lt;/P&gt;&lt;P&gt;HTTP Event Collector in Splunk:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment Details:&lt;BR /&gt;&lt;/STRONG&gt;Splunk Version: Splunk Enterprise 9.2 (Trial License)&lt;BR /&gt;Operating System: Ubuntu 22.04&lt;/P&gt;&lt;P&gt;Gateways (Both Virtual running on : CheckPoint_FW4 and CheckPoint_FW3 [Cluster2]&lt;/P&gt;&lt;P&gt;Firewall Rules: Cleanup Rule to allow any communication for testing purposes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Potential Root Cause - &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Log Analysis:&lt;BR /&gt;&lt;/STRONG&gt;Ran Command: tail -20 /opt/CPotelcol/otelcol.log &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on CheckPoint_FW4&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Response: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/internal/bounded_memory_queue.go:47&lt;/P&gt;&lt;P&gt;2024-06-26T14:20:34.609+1000&amp;nbsp;&amp;nbsp;&amp;nbsp; error&amp;nbsp;&amp;nbsp; exporterhelper/queued_retry.go:391&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt; Exporting failed. The error is not retryable. Dropping data.&amp;nbsp;&amp;nbsp;&amp;nbsp; {"kind": "exporter", "data_type": "metrics", "name": "prometheusremotewrite", "error": "Permanent error: Permanent error: remote write returned HTTP status 401 Unauthorized; err = %!w(&amp;lt;nil&amp;gt;): Bearer token not recognized. Please contact your Splunk admin.\n", "dropped_items": 284}&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*retrySender).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:391&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*metricsSenderWithObservability).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/metrics.go:125&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*queuedRetrySender).start.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:195&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper/internal.(*boundedMemoryQueue).StartConsumers.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Completed Installation Steps:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(&lt;/STRONG&gt;Text highlighted in Green completed)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Installed the Third-Party Monitoring Tool&lt;/LI&gt;&lt;LI&gt;Installed the OpenTelemetry Agent and OpenTelemetry Collector on the Check Point Server&lt;/LI&gt;&lt;LI&gt;Configured the OpenTelemetry Collector on the Check Point Server to work with the Third-Party Monitoring Tool: Splunk&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configure HTTP Event Collector on Splunk Enterprise&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Enable HTTP Event Collector on Splunk Enterprise&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Before you can use Event Collector to receive events through HTTP, you must enable it. For Splunk Enterprise, enable HEC through the&amp;nbsp;&lt;STRONG&gt;Global Settings&lt;/STRONG&gt;&amp;nbsp;dialog box.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Data Inputs&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;HTTP Event Collector&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Global Settings&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;In the&amp;nbsp;&lt;STRONG&gt;All Tokens&lt;/STRONG&gt;&amp;nbsp;toggle button, select&amp;nbsp;&lt;STRONG&gt;Enabled&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;(Optional) Choose a&amp;nbsp;&lt;STRONG&gt;Default Source Type&lt;/STRONG&gt;&amp;nbsp;for all HEC tokens. You can also type in the name of the source type in the text field above the drop-down list box before choosing the source type.&lt;/LI&gt;&lt;LI&gt;(Optional) Choose a&amp;nbsp;&lt;STRONG&gt;Default Index&lt;/STRONG&gt;&amp;nbsp;for all HEC tokens.&lt;/LI&gt;&lt;LI&gt;(Optional) Choose a&amp;nbsp;&lt;STRONG&gt;Default Output Group&lt;/STRONG&gt;&amp;nbsp;for all HEC tokens.&lt;/LI&gt;&lt;LI&gt;(Optional) To use a deployment server to handle configurations for HEC tokens, click the&amp;nbsp;&lt;STRONG&gt;Use Deployment Server&lt;/STRONG&gt;&amp;nbsp;check box.&lt;/LI&gt;&lt;LI&gt;(Optional) To have HEC listen and communicate over HTTPS rather than HTTP, click the&amp;nbsp;&lt;STRONG&gt;Enable SSL&lt;/STRONG&gt;&amp;nbsp;checkbox.&lt;/LI&gt;&lt;LI&gt;(Optional) Enter a number in the&amp;nbsp;&lt;STRONG&gt;HTTP Port Number&lt;/STRONG&gt;&amp;nbsp;field for HEC to listen on.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_0-1719463542110.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31524i6A6645533F45D0A1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_0-1719463542110.png" alt="Network007_0-1719463542110.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create an Event Collector token on Splunk Enterprise&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;To use HEC, you must configure at least one token.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Add Data&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;monitor&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;HTTP Event Collector&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;In the&amp;nbsp;&lt;STRONG&gt;Name&lt;/STRONG&gt;&amp;nbsp;field, enter a name for the token.&lt;/LI&gt;&lt;LI&gt;(Optional) In the&amp;nbsp;&lt;STRONG&gt;Source name override&lt;/STRONG&gt;&amp;nbsp;field, enter a source name for events that this input generates.&lt;/LI&gt;&lt;LI&gt;(Optional) In the&amp;nbsp;&lt;STRONG&gt;Description&lt;/STRONG&gt;&amp;nbsp;field, enter a description for the input.&lt;/LI&gt;&lt;LI&gt;(Optional) In the&amp;nbsp;&lt;STRONG&gt;Output Group&lt;/STRONG&gt;&amp;nbsp;field, select an existing forwarder output group.&lt;/LI&gt;&lt;LI&gt;(Optional) If you want to enable indexer acknowledgment for this token, click the&amp;nbsp;&lt;STRONG&gt;Enable indexer acknowledgment&lt;/STRONG&gt;&amp;nbsp;checkbox.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Next&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;(Optional) Confirm the source type and the index for HEC events.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_1-1719463542122.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31523i4CC07B56363D5AE5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_1-1719463542122.png" alt="Network007_1-1719463542122.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_2-1719463542126.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31525iEB0F4D5D7A4928A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_2-1719463542126.png" alt="Network007_2-1719463542126.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Click&amp;nbsp;&lt;STRONG&gt;Review&lt;/STRONG&gt;.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Confirm that all settings for the endpoint are what you want.&lt;/LI&gt;&lt;LI&gt;If all settings are what you want, click&amp;nbsp;&lt;STRONG&gt;Submit&lt;/STRONG&gt;. Otherwise, click&amp;nbsp;&lt;STRONG&gt;&amp;lt;&lt;/STRONG&gt;&amp;nbsp;to make changes.&lt;/LI&gt;&lt;LI&gt;(Optional) Copy the token value that Splunk Web displays and paste it into another document for reference later&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_3-1719463542128.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31527iC34D28C06A88C31D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_3-1719463542128.png" alt="Network007_3-1719463542128.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Confirmed the Token is Status: Enabled &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Configured payload-no-tls.json in /home/admin/payload-no-tls.json&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_4-1719463542133.png" style="width: 559px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31526i60EE7BEE0CE28F65/image-dimensions/559x301?v=v2" width="559" height="301" role="button" title="Network007_4-1719463542133.png" alt="Network007_4-1719463542133.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step&lt;/STRONG&gt;:&lt;BR /&gt;Run the configuration command to apply the payload - either the CLI command, or the Gaia REST API command: n Method 1 - Run the CLI command "sklnctl": a. Save the JSON payload in a file (for example, /home/admin/payload.json). b. Run this command: sklnctl export --set "$(cat /home/admin/payload.json)"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_5-1719463542135.png" style="width: 546px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31528i2CB494030EF60579/image-dimensions/546x107?v=v2" width="546" height="107" role="button" title="Network007_5-1719463542135.png" alt="Network007_5-1719463542135.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Repeated steps for FW4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_6-1719463542137.png" style="width: 570px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31530i12CC362A942274CE/image-dimensions/570x87?v=v2" width="570" height="87" role="button" title="Network007_6-1719463542137.png" alt="Network007_6-1719463542137.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rebooted Gateway FW3 and FW4&lt;/LI&gt;&lt;LI&gt;Rebooted Splunk Server&lt;/LI&gt;&lt;LI&gt;Restarted all Check Point Firewall Skyline Components&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Result: Data Failed to be ingested&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Other troubleshooting completed:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Created completely new token and repeated configuration steps&lt;/LI&gt;&lt;LI&gt;Updated the url within the payload.json file to end with&lt;UL&gt;&lt;LI&gt;/services/collector/raw&lt;/LI&gt;&lt;LI&gt;/services/collector/events&lt;/LI&gt;&lt;LI&gt;Updated “url”: &lt;A href="http://10" target="_blank" rel="noopener"&gt;http://10&lt;/A&gt;... Instead of https&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_7-1719463542138.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31529i2B7101A497FEA3A7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_7-1719463542138.png" alt="Network007_7-1719463542138.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Checked the Skyline Component Log Files for Troubleshooting&lt;/STRONG&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What are the relevant Check Point Skyline log files?&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;OpenTelemetry Collector:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;/opt/CPotelcol/otelcol.log&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CPView Exporter:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;/opt/CPviewExporter/otlp_cpview.log&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CPView API Service:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;$CPDIR/log/cpview_api_service.elg&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Logs CPView API Service and CPView displayed no logs indicating causes of the issues.&lt;/P&gt;&lt;P&gt;Confirmed that the bearer token works:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_8-1719463542139.png" style="width: 691px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31531iDA8BB04C045DDE16/image-dimensions/691x76?v=v2" width="691" height="76" role="button" title="Network007_8-1719463542139.png" alt="Network007_8-1719463542139.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result: Bearer Token accepted.&lt;/P&gt;&lt;P&gt;Confirmed Collector was healthy:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_9-1719463542141.png" style="width: 613px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31533i554BB03807AEC64F/image-dimensions/613x57?v=v2" width="613" height="57" role="button" title="Network007_9-1719463542141.png" alt="Network007_9-1719463542141.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Alternative payload-no-tls.json formats attempted:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_10-1719463542151.png" style="width: 536px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31532i9C66F4125E6451A5/image-dimensions/536x546?v=v2" width="536" height="546" role="button" title="Network007_10-1719463542151.png" alt="Network007_10-1719463542151.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_11-1719463542154.png" style="width: 558px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31534iCBE478E2AC881DB8/image-dimensions/558x288?v=v2" width="558" height="288" role="button" title="Network007_11-1719463542154.png" alt="Network007_11-1719463542154.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway Log Analysis (Returned everytime:)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SSH into CheckPoint_FW4 xx.xx.xx.xx via Remote Desktop&lt;/P&gt;&lt;P&gt;Ran Command: tail /opt/CPotelcol/otelcol.log&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Result: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/internal/bounded_memory_queue.go:47&lt;/P&gt;&lt;P&gt;2024-06-26T14:20:34.609+1000&amp;nbsp;&amp;nbsp;&amp;nbsp; error&amp;nbsp;&amp;nbsp; exporterhelper/queued_retry.go:391&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exporting failed. The error is not retryable. Dropping data.&amp;nbsp;&amp;nbsp;&amp;nbsp; {"kind": "exporter", "data_type": "metrics", "name": "prometheusremotewrite", "error": "Permanent error: Permanent error: remote write returned HTTP status 401 Unauthorized; err = %!w(&amp;lt;nil&amp;gt;): Bearer token not recognized. Please contact your Splunk admin.\n", "dropped_items": 284}&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*retrySender).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:391&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*metricsSenderWithObservability).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/metrics.go:125&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*queuedRetrySender).start.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:195&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper/internal.(*boundedMemoryQueue).StartConsumers.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Finding:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Appears to be an issue in which the HTTP Event Collector will not accept the Token Value, even when the token matches identically.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Could potentially be attributed to the payload-no-tls.json file not being formatted or compiled correctly on the Gateway.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2024 04:53:54 GMT</pubDate>
    <dc:creator>Network007</dc:creator>
    <dc:date>2024-06-27T04:53:54Z</dc:date>
    <item>
      <title>Help Needed: HTTP Event Collector Bearer Token not Recognized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-Needed-HTTP-Event-Collector-Bearer-Token-not-Recognized/m-p/691807#M115039</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Check Point Skyline - Splunk Configuration Issue: Unable to get Data In&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;Issue Summary: &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Splunk Enterprise Indexer will not accept HTTP Event Collector HEC_Token from Check Point Gateway resulting in no Skyline (Open Telemetry) data being ingested into Splunk.&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;I need help to get splunk indexer to recognise the token and allow data to be ingested.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please note this error was also replicated on different Splunk Instance to determine potential root cause. Could potentially be attributed to the payload-no-tls.json file not being formatted or compiled correctly on the Gateway.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Documentation used to configure set up:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Check Point Skyline Deployment:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178566" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk178566&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Official Check Point Skyline Guide PDF:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Appliances/Skyline/CP_Skyline_AdminGuide.pdf" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Appliances/Skyline/CP_Skyline_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Skyline Troubleshooting and FAQ:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk179870" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk179870&lt;/A&gt;&lt;/P&gt;&lt;P&gt;HTTP Event Collector in Splunk:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment Details:&lt;BR /&gt;&lt;/STRONG&gt;Splunk Version: Splunk Enterprise 9.2 (Trial License)&lt;BR /&gt;Operating System: Ubuntu 22.04&lt;/P&gt;&lt;P&gt;Gateways (Both Virtual running on : CheckPoint_FW4 and CheckPoint_FW3 [Cluster2]&lt;/P&gt;&lt;P&gt;Firewall Rules: Cleanup Rule to allow any communication for testing purposes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Potential Root Cause - &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Log Analysis:&lt;BR /&gt;&lt;/STRONG&gt;Ran Command: tail -20 /opt/CPotelcol/otelcol.log &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on CheckPoint_FW4&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Response: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/internal/bounded_memory_queue.go:47&lt;/P&gt;&lt;P&gt;2024-06-26T14:20:34.609+1000&amp;nbsp;&amp;nbsp;&amp;nbsp; error&amp;nbsp;&amp;nbsp; exporterhelper/queued_retry.go:391&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt; Exporting failed. The error is not retryable. Dropping data.&amp;nbsp;&amp;nbsp;&amp;nbsp; {"kind": "exporter", "data_type": "metrics", "name": "prometheusremotewrite", "error": "Permanent error: Permanent error: remote write returned HTTP status 401 Unauthorized; err = %!w(&amp;lt;nil&amp;gt;): Bearer token not recognized. Please contact your Splunk admin.\n", "dropped_items": 284}&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*retrySender).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:391&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*metricsSenderWithObservability).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/metrics.go:125&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*queuedRetrySender).start.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:195&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper/internal.(*boundedMemoryQueue).StartConsumers.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Completed Installation Steps:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(&lt;/STRONG&gt;Text highlighted in Green completed)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Installed the Third-Party Monitoring Tool&lt;/LI&gt;&lt;LI&gt;Installed the OpenTelemetry Agent and OpenTelemetry Collector on the Check Point Server&lt;/LI&gt;&lt;LI&gt;Configured the OpenTelemetry Collector on the Check Point Server to work with the Third-Party Monitoring Tool: Splunk&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configure HTTP Event Collector on Splunk Enterprise&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Enable HTTP Event Collector on Splunk Enterprise&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Before you can use Event Collector to receive events through HTTP, you must enable it. For Splunk Enterprise, enable HEC through the&amp;nbsp;&lt;STRONG&gt;Global Settings&lt;/STRONG&gt;&amp;nbsp;dialog box.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Data Inputs&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;HTTP Event Collector&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Global Settings&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;In the&amp;nbsp;&lt;STRONG&gt;All Tokens&lt;/STRONG&gt;&amp;nbsp;toggle button, select&amp;nbsp;&lt;STRONG&gt;Enabled&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;(Optional) Choose a&amp;nbsp;&lt;STRONG&gt;Default Source Type&lt;/STRONG&gt;&amp;nbsp;for all HEC tokens. You can also type in the name of the source type in the text field above the drop-down list box before choosing the source type.&lt;/LI&gt;&lt;LI&gt;(Optional) Choose a&amp;nbsp;&lt;STRONG&gt;Default Index&lt;/STRONG&gt;&amp;nbsp;for all HEC tokens.&lt;/LI&gt;&lt;LI&gt;(Optional) Choose a&amp;nbsp;&lt;STRONG&gt;Default Output Group&lt;/STRONG&gt;&amp;nbsp;for all HEC tokens.&lt;/LI&gt;&lt;LI&gt;(Optional) To use a deployment server to handle configurations for HEC tokens, click the&amp;nbsp;&lt;STRONG&gt;Use Deployment Server&lt;/STRONG&gt;&amp;nbsp;check box.&lt;/LI&gt;&lt;LI&gt;(Optional) To have HEC listen and communicate over HTTPS rather than HTTP, click the&amp;nbsp;&lt;STRONG&gt;Enable SSL&lt;/STRONG&gt;&amp;nbsp;checkbox.&lt;/LI&gt;&lt;LI&gt;(Optional) Enter a number in the&amp;nbsp;&lt;STRONG&gt;HTTP Port Number&lt;/STRONG&gt;&amp;nbsp;field for HEC to listen on.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_0-1719463542110.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31524i6A6645533F45D0A1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_0-1719463542110.png" alt="Network007_0-1719463542110.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create an Event Collector token on Splunk Enterprise&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;To use HEC, you must configure at least one token.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Add Data&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;monitor&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;HTTP Event Collector&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;In the&amp;nbsp;&lt;STRONG&gt;Name&lt;/STRONG&gt;&amp;nbsp;field, enter a name for the token.&lt;/LI&gt;&lt;LI&gt;(Optional) In the&amp;nbsp;&lt;STRONG&gt;Source name override&lt;/STRONG&gt;&amp;nbsp;field, enter a source name for events that this input generates.&lt;/LI&gt;&lt;LI&gt;(Optional) In the&amp;nbsp;&lt;STRONG&gt;Description&lt;/STRONG&gt;&amp;nbsp;field, enter a description for the input.&lt;/LI&gt;&lt;LI&gt;(Optional) In the&amp;nbsp;&lt;STRONG&gt;Output Group&lt;/STRONG&gt;&amp;nbsp;field, select an existing forwarder output group.&lt;/LI&gt;&lt;LI&gt;(Optional) If you want to enable indexer acknowledgment for this token, click the&amp;nbsp;&lt;STRONG&gt;Enable indexer acknowledgment&lt;/STRONG&gt;&amp;nbsp;checkbox.&lt;/LI&gt;&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Next&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;(Optional) Confirm the source type and the index for HEC events.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_1-1719463542122.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31523i4CC07B56363D5AE5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_1-1719463542122.png" alt="Network007_1-1719463542122.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_2-1719463542126.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31525iEB0F4D5D7A4928A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_2-1719463542126.png" alt="Network007_2-1719463542126.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Click&amp;nbsp;&lt;STRONG&gt;Review&lt;/STRONG&gt;.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Confirm that all settings for the endpoint are what you want.&lt;/LI&gt;&lt;LI&gt;If all settings are what you want, click&amp;nbsp;&lt;STRONG&gt;Submit&lt;/STRONG&gt;. Otherwise, click&amp;nbsp;&lt;STRONG&gt;&amp;lt;&lt;/STRONG&gt;&amp;nbsp;to make changes.&lt;/LI&gt;&lt;LI&gt;(Optional) Copy the token value that Splunk Web displays and paste it into another document for reference later&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_3-1719463542128.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31527iC34D28C06A88C31D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_3-1719463542128.png" alt="Network007_3-1719463542128.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Confirmed the Token is Status: Enabled &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Configured payload-no-tls.json in /home/admin/payload-no-tls.json&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_4-1719463542133.png" style="width: 559px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31526i60EE7BEE0CE28F65/image-dimensions/559x301?v=v2" width="559" height="301" role="button" title="Network007_4-1719463542133.png" alt="Network007_4-1719463542133.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step&lt;/STRONG&gt;:&lt;BR /&gt;Run the configuration command to apply the payload - either the CLI command, or the Gaia REST API command: n Method 1 - Run the CLI command "sklnctl": a. Save the JSON payload in a file (for example, /home/admin/payload.json). b. Run this command: sklnctl export --set "$(cat /home/admin/payload.json)"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_5-1719463542135.png" style="width: 546px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31528i2CB494030EF60579/image-dimensions/546x107?v=v2" width="546" height="107" role="button" title="Network007_5-1719463542135.png" alt="Network007_5-1719463542135.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Repeated steps for FW4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_6-1719463542137.png" style="width: 570px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31530i12CC362A942274CE/image-dimensions/570x87?v=v2" width="570" height="87" role="button" title="Network007_6-1719463542137.png" alt="Network007_6-1719463542137.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rebooted Gateway FW3 and FW4&lt;/LI&gt;&lt;LI&gt;Rebooted Splunk Server&lt;/LI&gt;&lt;LI&gt;Restarted all Check Point Firewall Skyline Components&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Result: Data Failed to be ingested&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Other troubleshooting completed:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Created completely new token and repeated configuration steps&lt;/LI&gt;&lt;LI&gt;Updated the url within the payload.json file to end with&lt;UL&gt;&lt;LI&gt;/services/collector/raw&lt;/LI&gt;&lt;LI&gt;/services/collector/events&lt;/LI&gt;&lt;LI&gt;Updated “url”: &lt;A href="http://10" target="_blank" rel="noopener"&gt;http://10&lt;/A&gt;... Instead of https&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_7-1719463542138.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31529i2B7101A497FEA3A7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Network007_7-1719463542138.png" alt="Network007_7-1719463542138.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Checked the Skyline Component Log Files for Troubleshooting&lt;/STRONG&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What are the relevant Check Point Skyline log files?&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;OpenTelemetry Collector:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;/opt/CPotelcol/otelcol.log&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CPView Exporter:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;/opt/CPviewExporter/otlp_cpview.log&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CPView API Service:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;$CPDIR/log/cpview_api_service.elg&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Logs CPView API Service and CPView displayed no logs indicating causes of the issues.&lt;/P&gt;&lt;P&gt;Confirmed that the bearer token works:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_8-1719463542139.png" style="width: 691px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31531iDA8BB04C045DDE16/image-dimensions/691x76?v=v2" width="691" height="76" role="button" title="Network007_8-1719463542139.png" alt="Network007_8-1719463542139.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result: Bearer Token accepted.&lt;/P&gt;&lt;P&gt;Confirmed Collector was healthy:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_9-1719463542141.png" style="width: 613px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31533i554BB03807AEC64F/image-dimensions/613x57?v=v2" width="613" height="57" role="button" title="Network007_9-1719463542141.png" alt="Network007_9-1719463542141.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Alternative payload-no-tls.json formats attempted:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_10-1719463542151.png" style="width: 536px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31532i9C66F4125E6451A5/image-dimensions/536x546?v=v2" width="536" height="546" role="button" title="Network007_10-1719463542151.png" alt="Network007_10-1719463542151.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network007_11-1719463542154.png" style="width: 558px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31534iCBE478E2AC881DB8/image-dimensions/558x288?v=v2" width="558" height="288" role="button" title="Network007_11-1719463542154.png" alt="Network007_11-1719463542154.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway Log Analysis (Returned everytime:)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SSH into CheckPoint_FW4 xx.xx.xx.xx via Remote Desktop&lt;/P&gt;&lt;P&gt;Ran Command: tail /opt/CPotelcol/otelcol.log&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Result: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/internal/bounded_memory_queue.go:47&lt;/P&gt;&lt;P&gt;2024-06-26T14:20:34.609+1000&amp;nbsp;&amp;nbsp;&amp;nbsp; error&amp;nbsp;&amp;nbsp; exporterhelper/queued_retry.go:391&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exporting failed. The error is not retryable. Dropping data.&amp;nbsp;&amp;nbsp;&amp;nbsp; {"kind": "exporter", "data_type": "metrics", "name": "prometheusremotewrite", "error": "Permanent error: Permanent error: remote write returned HTTP status 401 Unauthorized; err = %!w(&amp;lt;nil&amp;gt;): Bearer token not recognized. Please contact your Splunk admin.\n", "dropped_items": 284}&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*retrySender).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:391&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*metricsSenderWithObservability).send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/metrics.go:125&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper.(*queuedRetrySender).start.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; go.opentelemetry.io/collector/exporter@v0.82.0/exporterhelper/queued_retry.go:195&lt;/P&gt;&lt;P&gt;go.opentelemetry.io/collector/exporter/exporterhelper/internal.(*boundedMemoryQueue).StartConsumers.func1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Finding:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Appears to be an issue in which the HTTP Event Collector will not accept the Token Value, even when the token matches identically.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Could potentially be attributed to the payload-no-tls.json file not being formatted or compiled correctly on the Gateway.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 04:53:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-Needed-HTTP-Event-Collector-Bearer-Token-not-Recognized/m-p/691807#M115039</guid>
      <dc:creator>Network007</dc:creator>
      <dc:date>2024-06-27T04:53:54Z</dc:date>
    </item>
  </channel>
</rss>

