Splunk Cloud Platform

Getting error for hec token

Hemant_h
Engager

ERROR HttpInputDataHandler [3996076 HttpDedicatedIoThread-0] - Failed processing http input, token name=cnollc-cnoiwf-stg3.pegacloud.net, channel=n/a, source_IP=192.168.11.39, reply=1, events_processed=0, http_input_body_size=524, parsing_err=""

 

Getting this error , we have done configuration for dual ingestion .

The same Server is sending logs to both On-prem and Cloud env. How to fix these error

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Its the value that you would expect to be a GUID isnt it? I believe the name of the HEC token can be anything. As you suggested, if you're editing direct in inputs.conf you can set any token value - this is atleast still working in 9.4.1 anyway. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

0 Karma

Hemant_h
Engager

hi @livehybrid getting some more errors

00 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" timeout=30.0
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" File "/app/splunk/etc/apps/TA-mimecast-for-splunk/bin/ta_mimecast_for_splunk/aob_py3/modinput_wrapper/base_modinput.py", line 478, in send_http_request
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" proxy_uri=self._get_proxy_uri() if use_proxy else None)
0

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Are you using HEC or UF's s2s over http? Your token name is little bit weird to use as normal HEC token. Officially those format should be like GUID, but I know that at least with earlier versions also other formats have worked.
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Its the value that you would expect to be a GUID isnt it? I believe the name of the HEC token can be anything. As you suggested, if you're editing direct in inputs.conf you can set any token value - this is atleast still working in 9.4.1 anyway. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Hemant_h 

The reply=1 suggests that the token is disabled (see https://docs.splunk.com/Documentation/Splunk/9.4.1/Data/TroubleshootHTTPEventCollector#:~:text=Forbi...

Please can you confirm that the token is enabled on your destination?

You can also validate the token is working using https://<yourHECEndpoint>/services/collector/health?token=<yourToken> which should reply 

{"text":"HEC is healthy","code":17}

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Hemant_h
Engager

we are getting some more error would you please help me on that.

 

00 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" timeout=30.0
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" File "/app/splunk/etc/apps/TA-mimecast-for-splunk/bin/ta_mimecast_for_splunk/aob_py3/modinput_wrapper/base_modinput.py", line 478, in send_http_request
04-16-2025 04:07:19.696 -0400 ERROR ExecProcessor [2322799 ExecProcessorSchedulerThread] - message from "/app/splunk/bin/python3.7 /app/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_ttp_attachment_protect.py" proxy_uri=self._get_proxy_uri() if use_proxy else None)

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...