Splunk Cloud Platform

Unable to get data into Splunk Cloud using HEC

namratakar76
New Member

Hi All,

I am trying to get data into my Splunk Cloud trial account using HTTP event collector. After configuring the required steps for setting up HEC, I am executing the following command:

curl -k https://prd-<instance>.splunkcloud.com:8088/services/collector/event -H "Authorization: Splunk <token>"

However, I am getting the following error:

{"text": "The requested URL was not found on this server.","code":404}

Am I using the correct URL for this, or is this related to something in the configuration?  The tokens are enabled, and when I am checking the health of the instance, it returns this - {"text": "HEC is healthy","code":17}.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The standard form for the HEC URI in Splunk Cloud Platform free trials is:

https://http-inputs-<host>.splunkcloud.com:8088/<endpoint

See https://docs.splunk.com/Documentation/Splunk/8.2.4/Data/UsetheHTTPEventCollector#Send_data_to_HTTP_E...

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...