Getting Data In

Splunk Cloud - HTTP Event Collector Not Working

qcjacobo2577
Path Finder

We are using the latest version of Splunk Cloud.  I have configured HTTP Event Collection (HEC) token under "Settings" in the UI.  It is also worth noting that we are using SSO for user authentication.

I have attempted (numerous times) and failed to get a connection using curl (leveraging the information contained in this article: https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/HTTPEventCollectortokenmanagement).

All I get is "Failed to connect...".

I am wondering if there is something unique I need to do for Splunk Cloud, something unique with SSO, or if I can even send directly to Splunk Cloud (does the connection have to originate from a forwarder for  example).

Any advice is appreciated.

Labels (1)
0 Karma

qcjacobo2577
Path Finder

Here is the test I am running and the error I am seeing:

image.png

 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...