Security

POST HTTP event to splunk : call not properly authenticated- Why am I getting this?

rsarode
Engager

Trying to POST events to splunk using HTTP. This local on prem splunk installation.
For now I am getting this -

rsarode-mac:splunk rugvedsarode$ curl -k -H "Authorization: Splunk <MY-TOKEN-ID> https://localhost:8001/services/collector/event -d '{"event":"hello world"}'
<?xml version="1.0" encoding="UTF-8"?>
<response>
  <messages>
    <msg type="WARN">call not properly authenticated</msg>
  </messages>
</response>

I saw this but it did not help - https://answers.splunk.com/answers/406291/using-java-to-make-a-rest-api-call-to-splunk-why-a.html?ut...

I even tried to add "-u admin:". But still same issue.
Note my - mgmtHostPort = 127.0.0.1:8001

Furthermore, what is the corresponding header key value for curl "-k" option? Like we have
Content-Type: text/xml; OR
Connection: Keep-Alive;

TonyLeeVT
Builder

I had this same issue. There is a global settings button in the top right hand corner of the HTTP Event Collector screen. You may have a little warning symbol up there that states that you need to enable HEC within Global Settings.

0 Karma

DanPederEriksen
New Member

I experienced the same problem and did the following to solve it:

  1. Enable the http collector: "You enable it in self-service Splunk Cloud by going to Settings > Data Inputs > HTTP Event Collector > Global Settings, and then clicking Enabled"
  2. Create a http collector token.
  3. Restart splunk
  4. The following curl command then worked: curl -k -H "Authorization: Splunk " https://localhost:8088/services/collector/evenrcetype", "event": "http auth ftw!"}'

http://dev.splunk.com/view/event-collector/SP-CAAAE7G

0 Karma

alexbo27
New Member

the curl command in #4 is malformed... opening curly is missing, auth token? or it should be empty?

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...