Getting Data In

Step by Step process to send JSON using HEC

nareshinsvu
Builder

Hello experts,

I am no expert in java / json. I am new to splunk and comfortable with reading log/text files using forwarders in splunk. I have a requirement to read data from JSON Stream. I have setup HEC and able to send "Hello World" message as explained in some blogs. But couldn't find a procedure to push a URL data of live JSON feed.

Need someone to throw good light on it please.

Thanks,
Naresh

Tags (1)
0 Karma

niketn
Legend

@nareshinsvu you can check out following Splunk Wiki Talk topic where I have used POSTMAN to send out data through HEC to Splunk : Topic_5: HTTP Event Collector HEC in Windows using cURL with Postman

You should also check out couple of code repositories for some use cases of HEC: https://www.splunk.com/blog/2016/05/20/vote-using-splunk.html

There would be several examples in Splunk .Conf sessions for HTTP Event Collector as well.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@nareshinsvu

Can you please check JSON fields example from below link?

http://dev.splunk.com/view/event-collector/SP-CAAAFBZ

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...