Getting Data In

Step by Step process to send JSON using HEC

nareshinsvu
Builder

Hello experts,

I am no expert in java / json. I am new to splunk and comfortable with reading log/text files using forwarders in splunk. I have a requirement to read data from JSON Stream. I have setup HEC and able to send "Hello World" message as explained in some blogs. But couldn't find a procedure to push a URL data of live JSON feed.

Need someone to throw good light on it please.

Thanks,
Naresh

Tags (1)
0 Karma

niketn
Legend

@nareshinsvu you can check out following Splunk Wiki Talk topic where I have used POSTMAN to send out data through HEC to Splunk : Topic_5: HTTP Event Collector HEC in Windows using cURL with Postman

You should also check out couple of code repositories for some use cases of HEC: https://www.splunk.com/blog/2016/05/20/vote-using-splunk.html

There would be several examples in Splunk .Conf sessions for HTTP Event Collector as well.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@nareshinsvu

Can you please check JSON fields example from below link?

http://dev.splunk.com/view/event-collector/SP-CAAAFBZ

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...