Getting Data In

Proper URL for using Splunk HTTP Event Collector on free cloud account?

JimO
Explorer

Hi,

I believe I should be able to use Splunk HTTP Event Collector to send events to Splunk.  I have created an Event Collector token, I have tried a bunch of different URLs, none seem to work.  I have tried Curl and Postman.  For a free account if my URL is https://prd-p-m95xx.splunkcloud.com,  what would be my URL?

Here's my curl command 
curl "MysteryURL" -H "Authorization: Splunk 11111111-2222-3333-4444-555555555555" -d "{\"event\": \"Hello, Anyone!\", \"sourcetype\": \"manual\"}" -v

Thanks

Labels (1)
0 Karma
1 Solution

JimO
Explorer

Hi Rich,

Thanks again for your help.  My Firewall lets all outbound connections through.   Has a test I temporarily turned off my firewall, but still had the same issue.  I am baffled. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your URL should be https://http-inputs-prd-p-m95xx.splunkcloud.com:8088

curl -k https://http-inputs-prd-p-m95xx.splunkcloud.com:8088 -H "Authorization: Splunk 11111111-2222-3333-4444-555555555555" -d "{\"event\": \"Hello, Anyone!\", \"sourcetype\": \"manual\"}" -v

 

---
If this reply helps you, Karma would be appreciated.

JimO
Explorer

Hi,

Thanks for the reply.  I had tried that earlier, and I just did again.  this is what I got

C:\>curl -k https://http-inputs-prd-p-m95xx.splunkcloud.com:8088 -H "Authorization: Splunk 11111111-2222-3333-4444-555555555555" -d "{\"event\": \"Hello, Jojo!\", \"sourcetype\": \"manual\"}" -v
* Trying 143.244.220.150:8088...
* connect to 143.244.220.150 port 8088 failed: Timed out
* Failed to connect to http-inputs-prd-p-m95xx.splunkcloud.com port 8088 after 21158 ms: Couldn't connect to server
* Closing connection 0
curl: (28) Failed to connect to http-inputs-prd-p-m90yo.splunkcloud.com port 8088 after 21158 ms: Couldn't connect to server

So, I'm not sure what the issue is, but it looks like it is not the URL.  

Anyone else have any ideas?



0 Karma

richgalloway
SplunkTrust
SplunkTrust

Make sure your firewall is allowing connections to that host and port.

---
If this reply helps you, Karma would be appreciated.

JimO
Explorer
0 Karma

JimO
Explorer

JimO
Explorer
0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...