Getting Data In

Testing something on my Splunk Free at home using receivers/simple endpoint and all I'm getting is 404

PickleRick
SplunkTrust
SplunkTrust

I'm kinda lost here.

I'm trying to test something on my Splunk Free at home using receivers/simple endpoint and all I'm getting is 404.

The "normal" HEC endpoints work OK.

$ curl "http://172.16.0.3:8088/services/receivers/simple?source=www&sourcetype=web_event" -d "aaaaaaaaaaaaaa"
{"text":"The requested URL was not found on this server.","code":404}

It's the example almost literarily copied from REST API docs. And I'm getting 404.

Where to look for diagnostic info?

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust
You mentioned you didn't change the default management port 8089 but in your original post you are making request on 8088.
That confused me.

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

@PickleRick  - Two points sir, not sure if you have noticed in the document.

  1. It says that the user role requires "edit_tcp" capability.
  2. The example shows management port 8089.
    1. VatsalJagani_1-1649000468413.png

       

    2. VatsalJagani_0-1649000421768.png

PickleRick
SplunkTrust
SplunkTrust

As I wrote, I'm using Free License at home so I have no authentication and multiple users. In free version there is only one automatically authenticated admin user. Besides, if it was a case of permissions I'd rather expect a 403 or 401 than 404.

And the port of course is the same as the configuration. It's the common practice to set up the HTTP endpoint on 8089 when TLS is enabled. In my case I don't need TLS (quite the contrary - lack of TLS enables easier debugging) so I didn't change the default 8089 port.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust
You mentioned you didn't change the default management port 8089 but in your original post you are making request on 8088.
That confused me.

PickleRick
SplunkTrust
SplunkTrust

Right! I'm so used to sending over the HEC port, I didn't notice it was supposed to be sent to mgmt port!

Thanks.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...