Getting Data In

Can the HTTP Event Collector provide the channel identifier in the Splunk events

redbugz
New Member

We are sending data to the HTTP Event Collector raw endpoint from multiple systems, but we have no control over the data itself (coming from a third party). We are generating arbitrary channel identifiers for each system, but when we query the data the channel identifier is not present. Unfortunately the data itself does not provide a simple way to determine the system. The system name is sent in a special header, but I doubt the HEC is inspecting that header and I could find no documentation about HEC using headers other than the ones it specifies.

Is there a way to get either the channel identifier or an arbitrary header value used so we can determine which determine which system is sending the data and distinguish between the many systems using the HEC to send data?

0 Karma

dhihoriya_splun
Splunk Employee
Splunk Employee

Hi @redbugz

If you are sending data in Splunk via a different source (channel identifier) then you can search events for that particular source by below query :

source="http:(source_name OR channel identifier)"

Example:
As here let's take one example if you have created one HEC token and its name is "network_demo" and that is for your network instance logs then you can search particular network logs by searching source="http:network_demo".

For more information about HEC, Please follow below doc:
http://dev.splunk.com/view/event-collector/SP-CAAAE7F

Thanks,
Dixit

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...