Getting Data In

Issues with HTTP Status for HEC token

SplunkDash
Motivator

Hey,

I am facing following issues when sending data using HEC token. Connection has been established with no issue but getting following error message with HEC. Any recommendations to resolve this issue will be highly appreciated. Thank you!

 

SplunkDash_0-1731871275825.png

 

[http]
disabled = 0
enableSSL = 0

is also there.

 

Tags (1)
0 Karma
1 Solution

SplunkDash
Motivator

Hello,

The issues got resolved. The port 8088 was used by other services causing that issue, had to kill that service to resolve that issue. Now working as expected. Thank you so much all.

View solution in original post

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. It's much more convenient (and lets people search the content later) if you copy-paste text instead of posting pictures (structured text is best pasted into a preformatted-style paragraph or a code block.

2. Here we only see the result of your action. We have no idea what exactly you did.

SplunkDash
Motivator

Hey @PickleRick 

I was testing using this: 

curl -k http://splunk-hf-1729440419.us-east-1.alb.amazonaws.com:8088/services/collector -H "Authorization: Splunk ad9fe08e-68fb-4b07-876b-94f00bdd0d91" -d '{"event": "Hec Splunk Test"}' -v

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
After you have pasted whole url and token, please remove that token and generate a new one. Otherwise you could surprise how many will try it!
It’s best to anonymous both url (host part) and token before you post those to community.

SplunkDash
Motivator

Hey @isoutamo 

Thank you for letting me know. But the token and the host URL provided are not the actual, I changed them a little. We should be fine. Thank you so much again.

0 Karma

dural_yyz
Motivator

Your URL is short.

https://http-inputs-<customer>.splunkcloud.com/services/collector/raw
or
https://mysplunkserver.example.com:8088/services/collector/event

SplunkDash
Motivator

Hello,

The issues got resolved. The port 8088 was used by other services causing that issue, had to kill that service to resolve that issue. Now working as expected. Thank you so much all.

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...