Hi,
We have created a custom events index 'abcde' in Splunk Enterprise, but sending data to it with cURL always fail. If the index is 'main', it works fine.
Could you please investigate this issue?
Kind regards,
Moacir
Hi,
I have forgotten to add it to "Select Allowed Indexes" in the HEC token. Now it works fine 🙂
Thanks,
Moacir
How did you create the index? On which instance was it created?
How does curl fail? What error is returned?
Hi,
I have forgotten to add it to "Select Allowed Indexes" in the HEC token. Now it works fine 🙂
Thanks,
Moacir