<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can someone help us with our HTTP event collector 400 error? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453789#M93989</link>
    <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;Does anybody know which is the file logs where we could check if the syntax of a HTTP post request is correct?&lt;/P&gt;

&lt;P&gt;Our issue is that our system sent an HTTP POST to Splunk and it received a 400 error. &lt;BR /&gt;
We see that this message could be: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.0/Data/TroubleshootHTTPEventCollector"&gt;1&lt;/A&gt;&lt;BR /&gt;
5   400 Bad Request No data&lt;BR /&gt;
6   400 Bad Request Invalid data format&lt;BR /&gt;
7   400 Bad Request Incorrect index&lt;BR /&gt;
...&lt;BR /&gt;
0   400 Bad Request Data channel is missing&lt;BR /&gt;
11  400 Bad Request Invalid data channel&lt;BR /&gt;
12  400 Bad Request Event field is required&lt;BR /&gt;
13  400 Bad Request Event field cannot be blank&lt;BR /&gt;
14  400 Bad Request ACK is disabled&lt;BR /&gt;
15  400 Bad Request Error in handling indexed fields&lt;BR /&gt;
16  400 Bad Request Query string authorization is not enabled&lt;/P&gt;

&lt;P&gt;Anybody know how we could check the status code of the bad requests?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;

&lt;P&gt;Best Regards&lt;/P&gt;</description>
    <pubDate>Fri, 26 Oct 2018 16:59:41 GMT</pubDate>
    <dc:creator>sito82viso</dc:creator>
    <dc:date>2018-10-26T16:59:41Z</dc:date>
    <item>
      <title>Can someone help us with our HTTP event collector 400 error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453789#M93989</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;Does anybody know which is the file logs where we could check if the syntax of a HTTP post request is correct?&lt;/P&gt;

&lt;P&gt;Our issue is that our system sent an HTTP POST to Splunk and it received a 400 error. &lt;BR /&gt;
We see that this message could be: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.0/Data/TroubleshootHTTPEventCollector"&gt;1&lt;/A&gt;&lt;BR /&gt;
5   400 Bad Request No data&lt;BR /&gt;
6   400 Bad Request Invalid data format&lt;BR /&gt;
7   400 Bad Request Incorrect index&lt;BR /&gt;
...&lt;BR /&gt;
0   400 Bad Request Data channel is missing&lt;BR /&gt;
11  400 Bad Request Invalid data channel&lt;BR /&gt;
12  400 Bad Request Event field is required&lt;BR /&gt;
13  400 Bad Request Event field cannot be blank&lt;BR /&gt;
14  400 Bad Request ACK is disabled&lt;BR /&gt;
15  400 Bad Request Error in handling indexed fields&lt;BR /&gt;
16  400 Bad Request Query string authorization is not enabled&lt;/P&gt;

&lt;P&gt;Anybody know how we could check the status code of the bad requests?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;

&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 16:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453789#M93989</guid>
      <dc:creator>sito82viso</dc:creator>
      <dc:date>2018-10-26T16:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone help us with our HTTP event collector 400 error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453790#M93990</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;Is the index name is configured correctly while token was created ?&lt;BR /&gt;
Is correct token has been used for sending the data ?&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 14:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453790#M93990</guid>
      <dc:creator>iamarkaprabha</dc:creator>
      <dc:date>2018-10-27T14:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone help us with our HTTP event collector 400 error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453791#M93991</link>
      <description>&lt;P&gt;@iamarkaprabha converted answer to comment, since you have asked for further details. This will keep the question as unanswered for others to assist.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 20:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453791#M93991</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-10-27T20:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone help us with our HTTP event collector 400 error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453792#M93992</link>
      <description>&lt;P&gt;Thanks Niket&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 04:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453792#M93992</guid>
      <dc:creator>iamarkaprabha</dc:creator>
      <dc:date>2018-10-28T04:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone help us with our HTTP event collector 400 error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453793#M93993</link>
      <description>&lt;P&gt;Hi @iamarkprabha, as index name and token haven't been modified so we can discard these reason. The main problem is that we aren't able to check how it is the syntax of the http request that the system sends, so we thought that the best solution should be to check on the Splunk server side. Do you know if splunk has a log file where we could check the syntax of the malformed http request? &lt;BR /&gt;
Thank you &lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 06:30:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453793#M93993</guid>
      <dc:creator>sito82viso</dc:creator>
      <dc:date>2018-10-29T06:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone help us with our HTTP event collector 400 error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453794#M93994</link>
      <description>&lt;P&gt;This is the splunk issue in 7.2 it seems , we have had the same issue where we are seeing tons of log saying &lt;CODE&gt;ERROR HttpInputDataHandler - Parsing error : Error in handling indexed fields&lt;/CODE&gt; , we are using the same token across our nodes and splunk 6.6 version works fine with the same set of jsons we are sending but the once we tried the same requests using HEC in splunk 7.2 , we have started to see these issues.&lt;/P&gt;

&lt;P&gt;Can somebody please let us know if they had seen any changes from 6.6 to 7.2 for Http event collector feeding data differently now.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 11:58:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453794#M93994</guid>
      <dc:creator>vguptadevops</dc:creator>
      <dc:date>2018-12-17T11:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone help us with our HTTP event collector 400 error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453795#M93995</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;Anybody know how we could check the status code of the bad requests?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;This is in the response body or content of the request. It will include the code and text description. Below is an example of the incorrect index response:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;{"text":"Incorrect index","code":7,"invalid-event-number":1}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Apr 2019 20:28:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-help-us-with-our-HTTP-event-collector-400-error/m-p/453795#M93995</guid>
      <dc:creator>twhite_splunk</dc:creator>
      <dc:date>2019-04-04T20:28:46Z</dc:date>
    </item>
  </channel>
</rss>

