Getting Data In

Why would a Rest API receiver drop an event?

jwhughes58
Contributor

We have a double feed from a FireEye device going into Splunk. The idea is to convert from XML over syslog to JSON over port 8089. A comparison done yesterday found an event that Splunk received as XML but it never received the JSON version. Are there any logs that capture events on port 8089? I'm trying to see if there was an error message generated. I had the device owner manually send the event today and Splunk received it without issue. I need to make certain that Splunk receives all JSON events over port 8089 or generates an error when we make the final cutover.

TIA
Joe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...