<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP event collector 404 error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247557#M47751</link>
    <description>&lt;P&gt;HEC configs are in $SPLUNK_HOME/etc/apps/splunk_httpinput&lt;BR /&gt;
Did you check that you turned HEC back on in the Global Settings button after reinstall? I believe you can create tokens and not have the option "on".&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 11:23:52 GMT</pubDate>
    <dc:creator>starcher</dc:creator>
    <dc:date>2020-09-29T11:23:52Z</dc:date>
    <item>
      <title>HTTP event collector 404 error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247556#M47750</link>
      <description>&lt;P&gt;Good Day &lt;/P&gt;

&lt;P&gt;I've got two issues with my HTTP event collector.&lt;/P&gt;

&lt;P&gt;1st issue:&lt;BR /&gt;
I created an event collector when I installed Splunk 6.3, that worked fine I since then upgraded to splunk 6.5 -  I then deleted my event collector but was still able to POST to the URL&lt;/P&gt;

&lt;P&gt;I then uninstalled splunk from my server,  and installed it from scratch but still experienced the issue above, Does anyone know where I could look to see why the HEC configurations still remain&lt;/P&gt;

&lt;P&gt;2nd Issue&lt;BR /&gt;
Whenever I add a new HEC i get the following error&lt;BR /&gt;
{&lt;BR /&gt;
  "text": "The requested URL was not found on this server.",&lt;BR /&gt;
  "code": 404&lt;BR /&gt;
}&lt;/P&gt;

&lt;P&gt;I have read all the docs and lots of blog posts, with no luck of how to resolve these issues&lt;/P&gt;

&lt;P&gt;I am using google Postman and Curl run a post to my HEC&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Edson&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 11:58:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247556#M47750</guid>
      <dc:creator>evanwyk11</dc:creator>
      <dc:date>2016-10-14T11:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP event collector 404 error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247557#M47751</link>
      <description>&lt;P&gt;HEC configs are in $SPLUNK_HOME/etc/apps/splunk_httpinput&lt;BR /&gt;
Did you check that you turned HEC back on in the Global Settings button after reinstall? I believe you can create tokens and not have the option "on".&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247557#M47751</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2020-09-29T11:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP event collector 404 error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247558#M47752</link>
      <description>&lt;P&gt;Hi starcher&lt;/P&gt;

&lt;P&gt;I have checked that the HEC is turned on in the global settings, I have two tokens created. But currently only the one token works and the other token gives me a 404 error - both are configured the same.&lt;BR /&gt;
Are there any other setting that I am missing?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 12:00:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247558#M47752</guid>
      <dc:creator>evanwyk11</dc:creator>
      <dc:date>2016-10-17T12:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP event collector 404 error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247559#M47753</link>
      <description>&lt;P&gt;You can try running btool and see if it lists your other token and what app it is coming from.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;splunk cmd btool --debug inputs list http&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Sun, 30 Oct 2016 21:34:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247559#M47753</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2016-10-30T21:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP event collector 404 error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247560#M47754</link>
      <description>&lt;P&gt;check etc/local/inputs.conf - I've seen upgrades reset the "disabled" setting in there from 0 to 1&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 20:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-event-collector-404-error/m-p/247560#M47754</guid>
      <dc:creator>andrewjgriffin</dc:creator>
      <dc:date>2017-06-14T20:31:30Z</dc:date>
    </item>
  </channel>
</rss>

