Getting Data In

Does the HTTP Event Collector API support events with arbitrary metadata? (2019 edition)

olivercole
New Member

3 years ago, someone asked my exact question:

"Does the HTTP Event Collector API support events with arbitrary metadata?" (can't add a link, no karma)

In short, POSTing {"event": "hello world", "foo": "bar"} results in {"text":"No data","code":5}.

Has the answer changed significantly in the intervening time? If so, in which version, and is there any documentation?

I'm using logstash 5.6 as a client.

0 Karma

starcher
Influencer

What is it you are trying to solve? Because it depends what you mean by metadata and if you can control the HEC payload.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...