Splunk Cloud Platform

HTTP Event Collector- Is there something wrong with this curl command?

splunkerhtml
Loves-to-Learn

hI

Currently trying to test an HTTP event collector token by directly sending events to the cloud before we use the HEC for a OpenTelemetry Connector, but we are getting stuck at 403 Forbidden error. Is there something wrong with this curl command? 

Not sure if it affects anything but we are still on the Splunk Cloud Classic

Screenshots attached, appreciate any help we can get!&.PNG

0 Karma

splunkerhtml
Loves-to-Learn

Hello, I tested my curl is now working but I always get this error with Mulesoft HEC

0 Karma

inventsekar
SplunkTrust
SplunkTrust

For those who like to learn the different error codes and their details:

Possible error codes

The following status codes have particular meaning for all HTTP Event Collector endpoints:

Status code HTTP status code ID HTTP status code Status message

0200OKSuccess
1403ForbiddenToken disabled
2401UnauthorizedToken is required
3401UnauthorizedInvalid authorization
4403ForbiddenInvalid token
5400Bad RequestNo data
6400Bad RequestInvalid data format
7400Bad RequestIncorrect index
8500Internal ErrorInternal server error
9503Service UnavailableServer is busy
10400Bad RequestData channel is missing
11400Bad RequestInvalid data channel
12400Bad RequestEvent field is required
13400Bad RequestEvent field cannot be blank
14400Bad RequestACK is disabled
15400Bad RequestError in handling indexed fields
16400Bad RequestQuery string authorization is not enabled

 

more info on HEC troubleshooting:

https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/TroubleshootHTTPEventCollector

 

thanks, have a great day! 

richgalloway
SplunkTrust
SplunkTrust

Error 403 means the token is incorrect or disabled.  Check that the curl command has the right token.

---
If this reply helps you, Karma would be appreciated.

splunkerhtml
Loves-to-Learn

splunkerhtml_0-1702888942331.png

Is this perhaps due to some configuration here, no?

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Might be. I'm not very strong on Cloud.

0 Karma

splunkerhtml
Loves-to-Learn

My token is valid, I tried with 2 differents token created 😞

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @splunkerhtml, may i know, after creating the token, did you do copy-paste ?!?!
after pasting, maybe, thee is a chance that, you included a space and entered ?!?! (many times many of my friends faced this issue!)
just double check the token created and copy pasted, then update us, thanks. 

or, is this a production project?.. then you may contact Splunk Cloud Support. they should be able to help you. 


Upvotes / karma points are appreciated by everybody, thanks. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, your HEC input disagrees with you.

If your data was wrong you'd get a different code (typically a round 400).

403 means that your token doesn't match the allowed tokens.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...