Hi everybody,
According to the official documentation the standard form for the HEC URI in self-service Splunk Cloud is as follows:
<protocol>://input-<host>:<port>/<endpoint>
However it fails and the form that does work is
<protocol>://<host>:<port>/<endpoint>
I am on Splunk Cloud self-managed (trial).
Has anyone had a similar experience? Is it possible that the Splunk team has made some changes without updating the documentation?
Thank you!
It's possible. Submit feedback on that documentation page and the docs team will investigate and make the necessary changes.
Cool, will do.
I'd still appreciate if other people who had similar experiences could share 🙂