<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I display data in Splunk that's delivered through the HTTP collector endpoint? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409003#M72542</link>
    <description>&lt;P&gt;If you have success, data is in Splunk. Check the &lt;CODE&gt;index=main&lt;/CODE&gt; if it is the case that you have set HEC to index it there.&lt;/P&gt;

&lt;P&gt;Search for &lt;CODE&gt;source="http:&amp;lt;your_hec_input_name&amp;gt;" (index="main")&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Feb 2019 18:30:34 GMT</pubDate>
    <dc:creator>tiagofbmm</dc:creator>
    <dc:date>2019-02-26T18:30:34Z</dc:date>
    <item>
      <title>How do I display data in Splunk that's delivered through the HTTP collector endpoint?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409002#M72541</link>
      <description>&lt;P&gt;I'm running a cloud trial of Splunk and have set up an HTTP collector. Data is being delivered to the endpoint via cURL.  See the following command and response:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;curl -k  &lt;A href="https://input-prd-p-lmgm59gf8vp3.cloud.splunk.com:8088/services/collector" target="test_blank"&gt;https://input-prd-p-lmgm59gf8vp3.cloud.splunk.com:8088/services/collector&lt;/A&gt; -H "Authorization: Splunk 3c95e4e7-daa7-4c57-94b9-6f9df02c16d7" -d '{"event": "hello world"}'

{"text":"Success","code":0}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Despite repeated execution of the command, the Data Summary remains blank.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6620iA139E543607F8EFC/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Does anyone know how to display the data submitted through cURL?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 18:10:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409002#M72541</guid>
      <dc:creator>mcforgerock</dc:creator>
      <dc:date>2019-02-26T18:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do I display data in Splunk that's delivered through the HTTP collector endpoint?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409003#M72542</link>
      <description>&lt;P&gt;If you have success, data is in Splunk. Check the &lt;CODE&gt;index=main&lt;/CODE&gt; if it is the case that you have set HEC to index it there.&lt;/P&gt;

&lt;P&gt;Search for &lt;CODE&gt;source="http:&amp;lt;your_hec_input_name&amp;gt;" (index="main")&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 18:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409003#M72542</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-02-26T18:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do I display data in Splunk that's delivered through the HTTP collector endpoint?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409004#M72543</link>
      <description>&lt;P&gt;Thanks for the response. I think I have this right but am still not seeing any search results.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6615i66978F69A904AD04/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6616iDC43E8FF4B40818B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Perhaps I'm missing something obvious?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 18:58:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409004#M72543</guid>
      <dc:creator>mcforgerock</dc:creator>
      <dc:date>2019-02-26T18:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I display data in Splunk that's delivered through the HTTP collector endpoint?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409005#M72544</link>
      <description>&lt;P&gt;Check that for AllTime, I don't know when did you ingest that dummy data and it will have the time of when you indexed it.&lt;/P&gt;

&lt;P&gt;If still no results, is this a Single Splunk Instance? &lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 09:59:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409005#M72544</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-02-27T09:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I display data in Splunk that's delivered through the HTTP collector endpoint?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409006#M72545</link>
      <description>&lt;P&gt;Still, nothing even when I change the range, see screenshot below. If the system is holding data shouldn't that be reflected in the data summary? Provided a screenshot of that as well.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6618i4C46D87C19C59ABA/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6619iE6672665CBFC6B75/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 15:14:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409006#M72545</guid>
      <dc:creator>mcforgerock</dc:creator>
      <dc:date>2019-02-27T15:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I display data in Splunk that's delivered through the HTTP collector endpoint?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409007#M72546</link>
      <description>&lt;P&gt;Try this (set &lt;CODE&gt;Time picker&lt;/CODE&gt; to &lt;CODE&gt;All time&lt;/CODE&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[|tstats max(_time) AS time WHERE index=* AND TERM("hello world") BY host source sourcetype index
| format
| rex field=search mode=sed "s/time/earliest/"] hello world
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Cut and paste this EXACTLY as-is.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 02:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-display-data-in-Splunk-that-s-delivered-through-the/m-p/409007#M72546</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-03T02:20:06Z</dc:date>
    </item>
  </channel>
</rss>

