Getting Data In

URL error for HEC - Cloud

Redwood
Loves-to-Learn Lots

Hi all, 

I am a bit of a newbie here, and am trying to setup HEC on splink cloud, however the URL I have created following the event collector documentation ( https://docs.splunk.com/Documentation/SplunkCloud/8.0.2007/Data/UsetheHTTPEventCollector)  doesn't appear to be working. Looking at the HEC dashboard occasionally there is some activity showing, but it tells me the URL is incorrect. I have tried numerous changes to the URL, and followed tons of advice on here, but nothing appears to be working. I am clearly missing something, and would really appreciate some guidance.

https://http-inputs-myhostname.splunkcloud.com:443//services/collector/event/authorisationheader

I have tried replacing event for raw, changed the port, although using a Splunk Cloud Platform instance rather then free trial. I have removed SSL and re-enabled.

I would be very grateful of any advice and support here.

Thank you

 

 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Redwood 
( https://docs.splunk.com/Documentation/SplunkCloud/8.0.2007/Data/UsetheHTTPEventCollector)
may i know why do you use the 8.0.2007 documentation pls. 

unless you want a particular doc version, maybe pls use - "latest" instead of that version number, so you will get the right documentation

 https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector#Configure_HTT...

Regarding the error, pls check the previous reply and let us know if its working or not, then we can troubleshoot further, thanks. 

 

Best Regards

Sekar

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Remove "authorisationheader" from the URL.  That's not a valid HEC URL.

If that doesn't help, then please post the exact text of the error message(s) you see and also identify the "it" that tells you the URL is incorrect.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...