Getting Data In

how to pass "fields" parameter in services/collector rest api?

mmah123
New Member

Hello Experts,
I am working on HEC rest api's /services/collector. Passing fields as given in the examples but getting "no data" error. Is there any configuration i need to take care?

Eg: {"event": "something happened", "fields": {"severity": "INFO", "category": ["foo", "bar"]}

Error:
{
"text": "No data",
"code": 5
}

Thanks in advance!
Mamatha M

Tags (2)
0 Karma

jagadeeshm
Contributor

HEC will not allow you to pass arbitrary metadata fields. "fields" is not a required field in the HEC protocol. Only the following are supported at the movement -

{
    "time": 1426279439, 
    "host": "localhost",
    "source": "datasource",
    "sourcetype": "txt",
    "index": "main",
    "event": { "hello": "world" }
}
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...