All Apps and Add-ons

Heroku https drain to splunk enterprise

klops
Explorer

Does anyone have luck processing heroku's https drain to a on-prem Splunk Enterprise indexer?

I'm currently using its syslog drain but want to add encryption and heroku https drain seem to be the only way.

From what I tell we'll need to setup a intermediate web server to process the https post from heroku, default splunk enterprise doesn't seem to have direct ingestion on http post.

Any recommendation is appreciated. Thanks

Tags (1)
0 Karma
1 Solution

klops
Explorer

Answering my own question. We ended up using a simple nginx server setup to just relay all the https POST into log files, and have a generic splunk universal forwarder on the nginx host to send the log over.

specific nginx setup is inspired by this stackoverflow post:
http://stackoverflow.com/questions/4939382/logging-post-data-from-request-body

View solution in original post

0 Karma

klops
Explorer

Answering my own question. We ended up using a simple nginx server setup to just relay all the https POST into log files, and have a generic splunk universal forwarder on the nginx host to send the log over.

specific nginx setup is inspired by this stackoverflow post:
http://stackoverflow.com/questions/4939382/logging-post-data-from-request-body

0 Karma
Get Updates on the Splunk Community!

Cloud Platform | Customer Change Announcement: Email Notification Will Be Available ...

The Notification Team is migrating our email service provider since currently there’s no support ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...