<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Cloud  Integration in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749497#M119076</link>
    <description>&lt;P&gt;I tried this curl command and got this output&lt;BR /&gt;&lt;BR /&gt;curl -k &lt;A href="https://&amp;lt;splunkcloud" target="_blank"&gt;https://&amp;lt;splunkcloudlink&lt;/A&gt;&amp;gt;:8088/services/collector/event -H "Authorization: Splunk &amp;lt;hec token&amp;gt;" -d "{\"event\": \"hello from the other side\"}"&lt;BR /&gt;&lt;BR /&gt;Output:&lt;BR /&gt;{"text":"Success","code":0}&lt;BR /&gt;&lt;BR /&gt;what should i see next&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jul 2025 11:56:12 GMT</pubDate>
    <dc:creator>XOR</dc:creator>
    <dc:date>2025-07-09T11:56:12Z</dc:date>
    <item>
      <title>Prisma Cloud  Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749391#M119061</link>
      <description>&lt;P&gt;Guys i have Splunk Cloud , i created Http Event Collector &amp;amp; in prisma i gave url /service/collector&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but logs are not showing up in splunk .. my questions :&amp;nbsp; should i add port number after my http url ?&lt;BR /&gt;&lt;BR /&gt;after url is it&amp;nbsp; /service/collector or&amp;nbsp;/service/collector/events&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what should i check as i tesed my prisma said tested pass&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 11:51:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749391#M119061</guid>
      <dc:creator>XOR</dc:creator>
      <dc:date>2025-07-08T11:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud  Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749418#M119062</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309351"&gt;@XOR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You shouldnt need to add the port in the Prisma config as Splunk Cloud uses the default HTTPS port for HEC receiving. I assume the URL you used starts https:// ?&lt;/P&gt;&lt;P&gt;As far as I know there is no option to add an index into the &lt;A href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-splunk" target="_self"&gt;Prisma configuration&lt;/A&gt;&amp;nbsp;therefore the data will go into the default index you selected when you created the HEC token - Are you able to confirm that this is the index that you are checking in?&lt;/P&gt;&lt;P&gt;Regarding the&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;service/collector or&amp;nbsp;/service/collector/events, you should be able to use the first, or "/services/collector/event" - note no "S" on the end. Prisma Cloud sends HEC events so this is the correct endpoint to use.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 14:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749418#M119062</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-08T14:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud  Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749448#M119068</link>
      <description>&lt;P&gt;One more question should I go to hec and copy paste that link right ... Can you pls give me example how that hec link should be like.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eg my link look lke this &lt;A href="https://splunkcloudname.com/httpcollector" target="_blank"&gt;https://splunkcloudname.com/httpcollector&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 03:11:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749448#M119068</guid>
      <dc:creator>XOR</dc:creator>
      <dc:date>2025-07-09T03:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud  Integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749497#M119076</link>
      <description>&lt;P&gt;I tried this curl command and got this output&lt;BR /&gt;&lt;BR /&gt;curl -k &lt;A href="https://&amp;lt;splunkcloud" target="_blank"&gt;https://&amp;lt;splunkcloudlink&lt;/A&gt;&amp;gt;:8088/services/collector/event -H "Authorization: Splunk &amp;lt;hec token&amp;gt;" -d "{\"event\": \"hello from the other side\"}"&lt;BR /&gt;&lt;BR /&gt;Output:&lt;BR /&gt;{"text":"Success","code":0}&lt;BR /&gt;&lt;BR /&gt;what should i see next&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 11:56:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prisma-Cloud-Integration/m-p/749497#M119076</guid>
      <dc:creator>XOR</dc:creator>
      <dc:date>2025-07-09T11:56:12Z</dc:date>
    </item>
  </channel>
</rss>

