Getting Data In

URL error for HEC - Cloud

Redwood
Loves-to-Learn Lots

Hi all, 

I am a bit of a newbie here, and am trying to setup HEC on splink cloud, however the URL I have created following the event collector documentation ( https://docs.splunk.com/Documentation/SplunkCloud/8.0.2007/Data/UsetheHTTPEventCollector)  doesn't appear to be working. Looking at the HEC dashboard occasionally there is some activity showing, but it tells me the URL is incorrect. I have tried numerous changes to the URL, and followed tons of advice on here, but nothing appears to be working. I am clearly missing something, and would really appreciate some guidance.

https://http-inputs-myhostname.splunkcloud.com:443//services/collector/event/authorisationheader

I have tried replacing event for raw, changed the port, although using a Splunk Cloud Platform instance rather then free trial. I have removed SSL and re-enabled.

I would be very grateful of any advice and support here.

Thank you

 

 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Redwood 
( https://docs.splunk.com/Documentation/SplunkCloud/8.0.2007/Data/UsetheHTTPEventCollector)
may i know why do you use the 8.0.2007 documentation pls. 

unless you want a particular doc version, maybe pls use - "latest" instead of that version number, so you will get the right documentation

 https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector#Configure_HTT...

Regarding the error, pls check the previous reply and let us know if its working or not, then we can troubleshoot further, thanks. 

 

Best Regards

Sekar

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Remove "authorisationheader" from the URL.  That's not a valid HEC URL.

If that doesn't help, then please post the exact text of the error message(s) you see and also identify the "it" that tells you the URL is incorrect.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...