Getting Data In

How to determine you "host" name for an HEC endpoint

kcantrel
Explorer

Sorry for the newbie question, but I can't seem to figure out how to use HEC. I am using a free cloud account. I first went into Settings->Data Input and created a HEC and got the token. But, nowhere on that page does it tell me what the endpoint should be. I found this document, that talks about three different ways of creating a HEC depending on your software type. While I know I don't have Enterprise, is the free account a "Self Serve"? Or, a "Managed"?

I assume it is "Managed" because the first thing you are supposed to do is go to the "Global Settings" from the HEC page to enable HEC, however when I go to my HEC page there isn't a Global Setting link.  Now, if I follow the instructions there it says to go to Settings->Add Data->Monitor->HEC, which I did, but it appeared to just go through the same steps I did when I just went to Settings->Data Input. Regardless, I went through the process and got yet another token. Now, further down the document it has a "How to send data to the HEC" and shows this as the endpoint "<protocol>://input-<host>:<port>/<endpoint>" which is fine, except it doesn't tell you what "host" is. I figured it would be the same as the URL that I used to login: "prd-p-0qk3h.splunkcloud.com", however, the DNS entry for http-inputs-prd-p-0qk3h.splunkcloud.com doesn't exist, nor does input-prd-p-0qk3h.splunikcloud.com. So, at this point I am stuck.

If anyone can get me over this hurdle, I'd greatly appreciate it.

Labels (2)
0 Karma

hvibha
New Member

Please let me know how you were able to fix this? Even I am facing this issue where I am unable to get the Splunk endpoint. 

0 Karma

kcantrel
Explorer

Turns out what worked for me was: https: //  prd-p-0qk3h.splunkcloud.com:8088/services/collector/raw (I put spaces around the "//" to appease the bulletin board).

Note the "prd-p-0qk3h" was unique to my instance. I found that by looking at the URL when I was logged into the console. Also note that it will use a self signed certificate, so you'll have to ignore that SSL warning. But, other than that, it worked!

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...