Alerting

How to resolve splunkd error when sending Meraki Alerts to Splunk HTTP Event Collector Endpoint?

developmenttool
Loves-to-Learn Lots

I am trying to send Meraki Alerts to Splunk HEC Endpoint.

Please refer this URL to understand how we send Meraki alerts to receiving services. https://developer.cisco.com/meraki/webhooks/#!introduction/overview

I need to specify the Splunk endpoint and the shared secret in the Meraki webhook alert page as expected by Meraki. And here are the following details"

Webhook URL: Splunk Public Endpoint DNS(Backend will be heavy forwarder:8088)/services/collector/raw
Shared Secret: HEC token in that Heavy forwarder

Now when I hit the test option, the Meraki alerts are not flowing into Splunk and on detailed log Splunk analysis, we get the below error in our splunkd.log:

06-03-2020 17:12:23.556 +0200 ERROR HttpInputDataHandler - Failed processing http input, token name=n/a, channel=n/a, source_IP=****, reply=2, events_processed=0, http_input_body_size=878

I could see that Meraki is not able to send the shared secret key with Splunk token embedded and hence failing.
Any suggestion on fixing this would be of great help.

Labels (1)
0 Karma

ansif
Motivator

@developmenttool : Is this issue resolved? May I know how you ended up this integration?

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...