<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Event Collector for SC4S is giving Error Message in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759109#M120329</link>
    <description>&lt;P&gt;1. Why do you have a deployer if you have just two SHs (so no SH cluster).&lt;/P&gt;&lt;P&gt;2. Have you checked manually if you can post an event to your HEC endpoint?&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-data-in/collect-http-event-data/http-event-collector-examples" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-data-in/collect-http-event-data/http-event-collector-examples&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 08 Mar 2026 21:40:45 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2026-03-08T21:40:45Z</dc:date>
    <item>
      <title>HTTP Event Collector for SC4S is giving Error Message</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759101#M120327</link>
      <description>&lt;P&gt;We have configured a &lt;STRONG&gt;Splunk Enterprise distributed environment&lt;/STRONG&gt; with the following components:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;2 Search Heads (SH)&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;2 Indexers (IDX)&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;1 Management Node&lt;/STRONG&gt; (acting as &lt;STRONG&gt;Cluster Manager, License Manager, and Deployer&lt;/STRONG&gt;)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;1 Heavy Forwarder (HF)&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;1 Deployment Server (DS)&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;1 SC4S instance&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;During the &lt;STRONG&gt;SC4S configuration&lt;/STRONG&gt;, we are seeing errors in Splunk searches indicating that logs are not being properly forwarded through the &lt;STRONG&gt;HTTP Event Collector (HEC)&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Below are some of the events we see in the sc4s:event sourcetype:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;- - syslog-ng 139 - [meta sequenceId="8133"] &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Server disconnected while preparing messages for sending, trying again; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;driver='d_hec_fmt#0', location='root generator dest_hec:5:5', &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;worker_index='0', time_reopen='10', batch_size='84'&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;host = splunk-sys01&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;source = sc4s&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sourcetype = sc4s:events&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;- - syslog-ng 139 - [meta sequenceId="8131"] &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;http: Server returned with a 4XX (client errors) status code, which means we are not authorized or the URL is not found; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;url='&lt;A href="https://192.168.44.94:8088/services/collector/event" target="_blank" rel="noopener"&gt;https://192.168.44.94:8088/services/collector/event&lt;/A&gt;', &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;status_code='403', &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;response='{"text":"Invalid token","code":4}', &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;driver='d_hec_fmt#0', location='root generator dest_hec:5:5'&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;host = splunk-sys01&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;source = sc4s&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sourcetype = sc4s:events&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;We have already:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Enabled &lt;STRONG&gt;HEC&lt;/STRONG&gt; on the Splunk side&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Configured the &lt;STRONG&gt;HEC token&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Added the token and HEC endpoint in the &lt;STRONG&gt;SC4S env_file&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;Restarted the SC4S service&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;However, the logs indicate &lt;STRONG&gt;HTTP 403 – Invalid token&lt;/STRONG&gt; errors when SC4S attempts to send events to the HEC endpoint.&lt;/P&gt;&lt;H3&gt;Question&lt;/H3&gt;&lt;P&gt;What could be causing the Invalid Token&lt;STRONG&gt;&amp;nbsp;(HTTP 403)&lt;/STRONG&gt; error in this setup, and what troubleshooting steps should we follow to resolve the issue so that SC4S can successfully forward logs to the indexers?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-03-08 150544.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41689iD41969059F2D83B4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-03-08 150544.png" alt="Screenshot 2026-03-08 150544.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-03-08 103818.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41687i0D78B9BBEABC875F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-03-08 103818.png" alt="Screenshot 2026-03-08 103818.png" /&gt;&lt;/span&gt;"&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 09:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759101#M120327</guid>
      <dc:creator>mosaddek</dc:creator>
      <dc:date>2026-03-08T09:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector for SC4S is giving Error Message</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759109#M120329</link>
      <description>&lt;P&gt;1. Why do you have a deployer if you have just two SHs (so no SH cluster).&lt;/P&gt;&lt;P&gt;2. Have you checked manually if you can post an event to your HEC endpoint?&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-data-in/collect-http-event-data/http-event-collector-examples" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-data-in/collect-http-event-data/http-event-collector-examples&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 21:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759109#M120329</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-03-08T21:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector for SC4S is giving Error Message</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759171#M120331</link>
      <description>&lt;P&gt;Solved the Problem by creating the HEC in CM, and push it to all the Indexers.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2026 03:28:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759171#M120331</guid>
      <dc:creator>mosaddek</dc:creator>
      <dc:date>2026-03-10T03:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector for SC4S is giving Error Message</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759195#M120333</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316075"&gt;@mosaddek&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm the variable name used in&amp;nbsp;&lt;STRONG&gt;SC4S env_file&amp;nbsp;&lt;/STRONG&gt;for the token please?&lt;/P&gt;&lt;P&gt;Also can you confirm you're using the GUID for the HEC token and not the name of it? The token should be something like&amp;nbsp;d79f596e-2b07-46dc-a7e1-320d1e086580&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 06:07:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-for-SC4S-is-giving-Error-Message/m-p/759195#M120333</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-03-11T06:07:59Z</dc:date>
    </item>
  </channel>
</rss>

