Getting Data In

Step by Step process to send JSON using HEC

nareshinsvu
Builder

Hello experts,

I am no expert in java / json. I am new to splunk and comfortable with reading log/text files using forwarders in splunk. I have a requirement to read data from JSON Stream. I have setup HEC and able to send "Hello World" message as explained in some blogs. But couldn't find a procedure to push a URL data of live JSON feed.

Need someone to throw good light on it please.

Thanks,
Naresh

Tags (1)
0 Karma

niketn
Legend

@nareshinsvu you can check out following Splunk Wiki Talk topic where I have used POSTMAN to send out data through HEC to Splunk : Topic_5: HTTP Event Collector HEC in Windows using cURL with Postman

You should also check out couple of code repositories for some use cases of HEC: https://www.splunk.com/blog/2016/05/20/vote-using-splunk.html

There would be several examples in Splunk .Conf sessions for HTTP Event Collector as well.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@nareshinsvu

Can you please check JSON fields example from below link?

http://dev.splunk.com/view/event-collector/SP-CAAAFBZ

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...