Getting Data In

Why would a Rest API receiver drop an event?

jwhughes58
Contributor

We have a double feed from a FireEye device going into Splunk. The idea is to convert from XML over syslog to JSON over port 8089. A comparison done yesterday found an event that Splunk received as XML but it never received the JSON version. Are there any logs that capture events on port 8089? I'm trying to see if there was an error message generated. I had the device owner manually send the event today and Splunk received it without issue. I need to make certain that Splunk receives all JSON events over port 8089 or generates an error when we make the final cutover.

TIA
Joe

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...