Getting Data In

Splunk Cloud Trial HEC Not Working

Klaverblad
Explorer

Hi all,

I just started a trial for Splunk Cloud , my URL looks similar to this:

https://prd-p-s8qvw.splunkcloud.com/en-GB/app/launcher/home

 

I want to get data in with the HEC. I have read all the following documentation:

https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Data/UsetheHTTPEventCollector#Configure_H...

According to the documentation, my URL should look like this:

https://http-inputs-prd-p-s8qvw.splunkcloud.com:8088/services/collector/event

However this does not work. It seems the DNS cannot be resolved. My NodeJS gives "ENOTFOUND"

I have tried different options (HHTP / HTTPS, host, port etc):

None of these work. All give one of the following errors:
  • Error: getaddrinfo ENOTFOUND http-inputs-prd-p-s8qvw.splunkcloud.com
  • Error: read ECONNRESET
  • HTTP 400 Sent HTTP to port 443
  • HTTP 404 Not Found

Can anybody help me get this working?

 

Regards,

 

Lawrence

Labels (1)
0 Karma
1 Solution

Klaverblad
Explorer

It seems the company firewall blocked outbound traffic to 8088. Issue explained

View solution in original post

0 Karma

Klaverblad
Explorer

It seems the company firewall blocked outbound traffic to 8088. Issue explained

0 Karma

Klaverblad
Explorer

Note:

  • I have an active token that looks similar to this: c0865140-53b4-4b53-a2d1-9571d39a5de8
  • My HTTP request has the following header:
    Authorization: Splunk c0865140-53b4-4b53-a2d1-9571d39a5de8
  • MY Splunk Cloud settings show HEC configuration to have SSL enabled and port 8088 (though these settings are grayed out and cannot be adjusted)
0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...