Dashboards & Visualizations

Using HTML to execute a cURL command

jpofosho
Explorer

Hello all,

My ultimate goal is to have a button (or buttons) on a Splunk dashboard which will inform other users when they have left their desk.

my current method is to add a clickable button using HTML on a HTML converted dashboard which will execute a cURL command. The cURL command is used to send data via the HTTP Event Collector to an index which would have the latest status of each user. I am able to execute the cURL command just fine with what I have below in the CLI:

curl -k https://<HOST>:8088/services/collector -H 'Authorization: Splunk <TOKEN>' -d '{"sourcetype": "cURL", "event":"name=JOHN location=WEST status=OUT"}'

I've attempted to convert the cURL command to an HTML form for the dashboard but what I'm using doesn't pass the HEC token properly:

 <form ref='uploadForm' 
  id='uploadForm' 
 action='https://Splunk:<TOKEN>@<HOST>:8088/services/collector' 
  method='post' 
  encType="multipart/form-data">
    <input type='hidden' type="location" name="West" value="West" />
    <input type='hidden' type="name" name="John" value="John" />
    <input type='hidden' type="status" name="Out" value="Out" />
    <input type='submit' value='John is out' />
</form> 

When using the above HTML, I get the following error:

{"text":"Token is required","code":2}

Any guidance on how to pass the HEC token or a more efficient method would be greatly appreciated.

0 Karma

sanagari
New Member

Hi,
This link could be of some use to embed curl command to HTML.
https://www.embedcurl.com/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...