Getting Data In

Why are HTTP Event Collector events not appearing the index?

NickLaurent
New Member

Hello fellow Splunkers,
I need some help with HEC (HTTP Event Collector). The problem is that no events are appearing in any indexes. To simplify the issue I set up a test HEC config without SSL (http). I use the curl command with an event "Hello World!" I get a status 200 successful. Let nothing in the indexes.
Environment:
Windows 10, with Splunk Enterprise:
HEC, three unique Tokens with same Sourcetypes, different indexes.

1 Arduino setup to sent events via HEC
1 PI setup to send events via HEC
1 MAC for testing HEC using a curl command.

Thanks

Nick

0 Karma
1 Solution

starcher
Influencer

You will have to find someone's code or write your own for Arduino. But on a PI/Mac you can use Python and here is an existing HEC class for it. https://github.com/georgestarcher/Splunk-Class-httpevent

View solution in original post

0 Karma

starcher
Influencer

You will have to find someone's code or write your own for Arduino. But on a PI/Mac you can use Python and here is an existing HEC class for it. https://github.com/georgestarcher/Splunk-Class-httpevent

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...