Getting Data In

RE: HTTP Event Collector target index- Is there a way to specify in the curl command the target index?

mark-jones
Explorer

Hello,

Is there a way to specify in the curl command the target index?

For example with the following command, how can i target an index named: scheduler  in the command line?

curl -k https://prd-plot.splunkcloud.com:8088/services/collector -H "Authorization:Splunk #####-4f99-b680-72c7bd33f9bb" -d "{\"sourcetype\"😕"_json\",\"event\": {\"a\": \"value1\", \"b\": [\"value1_1\", \"value1_2\"]}}"
 
Thanks,
Mark
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You should be able to specify the index the same you do the sourcetype.

curl -k https://prd-plot.splunkcloud.com:8088/services/collector -H "Authorization:Splunk #####-4f99-b680-72c7bd33f9bb" -d "{\"sourcetype\":\"_json\",\"index\": \"scheduler\",\"event\": {\"a\": \"value1\", \"b\": [\"value1_1\", \"value1_2\"]}}"
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...