Hello Experts,
I am working on HEC rest api's /services/collector. Passing fields as given in the examples but getting "no data" error. Is there any configuration i need to take care?
Eg: {"event": "something happened", "fields": {"severity": "INFO", "category": ["foo", "bar"]}
Error:
{
"text": "No data",
"code": 5
}
Thanks in advance!
Mamatha M
HEC will not allow you to pass arbitrary metadata fields. "fields" is not a required field in the HEC protocol. Only the following are supported at the movement -
{
"time": 1426279439,
"host": "localhost",
"source": "datasource",
"sourcetype": "txt",
"index": "main",
"event": { "hello": "world" }
}