Splunk Cloud Platform

Getting error for hec token

Hemant_h
Engager

ERROR HttpInputDataHandler [3996076 HttpDedicatedIoThread-0] - Failed processing http input, token name=cnollc-cnoiwf-stg3.pegacloud.net, channel=n/a, source_IP=192.168.11.39, reply=1, events_processed=0, http_input_body_size=524, parsing_err=""

 

Getting this error , we have done configuration for dual ingestion .

The same Server is sending logs to both On-prem and Cloud env. How to fix these error

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Its the value that you would expect to be a GUID isnt it? I believe the name of the HEC token can be anything. As you suggested, if you're editing direct in inputs.conf you can set any token value - this is atleast still working in 9.4.1 anyway. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

0 Karma

Hemant_h
Engager

hi @livehybrid getting some more errors

00 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" timeout=30.0
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" File "/app/splunk/etc/apps/TA-mimecast-for-splunk/bin/ta_mimecast_for_splunk/aob_py3/modinput_wrapper/base_modinput.py", line 478, in send_http_request
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" proxy_uri=self._get_proxy_uri() if use_proxy else None)
0

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Are you using HEC or UF's s2s over http? Your token name is little bit weird to use as normal HEC token. Officially those format should be like GUID, but I know that at least with earlier versions also other formats have worked.
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Its the value that you would expect to be a GUID isnt it? I believe the name of the HEC token can be anything. As you suggested, if you're editing direct in inputs.conf you can set any token value - this is atleast still working in 9.4.1 anyway. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Hemant_h 

The reply=1 suggests that the token is disabled (see https://docs.splunk.com/Documentation/Splunk/9.4.1/Data/TroubleshootHTTPEventCollector#:~:text=Forbi...

Please can you confirm that the token is enabled on your destination?

You can also validate the token is working using https://<yourHECEndpoint>/services/collector/health?token=<yourToken> which should reply 

{"text":"HEC is healthy","code":17}

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Hemant_h
Engager

we are getting some more error would you please help me on that.

 

00 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" timeout=30.0
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" File "/app/splunk/etc/apps/TA-mimecast-for-splunk/bin/ta_mimecast_for_splunk/aob_py3/modinput_wrapper/base_modinput.py", line 478, in send_http_request
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" proxy_uri=self._get_proxy_uri() if use_proxy else None)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...