Getting Data In

Free trial- What is the correct HEC-url?

perl
New Member

Hi, 

I have recently created a splunk-cloud free trial. I then wanted to create a HEC-collector.  I went to : https://prd-p-aaaaa.splunkcloud.com/en-US/manager/launcher/http-eventcollector and added one.  (my id is different) 

I received a token aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa i then followed the the documentation here: https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/UsetheHTTPEventCollector

to create the url for the HEC-collector. It says to use:

<protocol>://http-inputs-<host>.splunkcloud.com:<port>/<endpoint>

so from my understanding it should become: 

https://http-inputs-prd-p-aaaaa.splunkcloud.com:8088/services/collector/raw  since i want to provide logs over json. 

However if i try to curl that url.. i get 

 

 

curl: (6) Could not resolve host: THE_CONFIGURED_HOST

 

 

So, what im asking is what is the correct url to use towards the free-trial HEC-collector?

 

BR

perl

Labels (1)
0 Karma

BG
Explorer

I recent struggled to get some event log data from an auth0 tier. I was using the same hostname format as you've used, on port 8088. Then I ended up looking at auth0's own documentation for getting data into Splunk via the http collector and it said port 443 was used. So I tried this and it worked🤔. I still don't know why, but it works so I'm leaving it alone for now.

perl
New Member

In this i think its something with the URL, since it can not be resolved at all. Once the host part has been resolved i could try a port change. 

0 Karma

perl
New Member

Its not in gcp.  And changeing the url from a '-' to a '.' does unfortunately nothing. if i try to curl it. i get the same result 

curl https://http-inputs.prd-p-aaaaa.splunkcloud.com:8088/services/collector/raw
curl: (6) Could not resolve host: http-inputs.prd-p-aaaaa.splunkcloud.com

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your cloud stack is in GCP then the URL is https://http-inputs.prd-p-aaaaa.splunkcloud.com:8088/services/collector/raw  

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...