Splunk Cloud

Enable http event collector

eltnegcoinprofi
Explorer

How can I use the HTTP event collector in Splunk cloud 15 days trial? Also, will my instance be disabled after the trial?

 

I followed the instructions here but I got {"text": "Data channel is missing", "code":10} and  Could not resolve host: when I tried the URLs `https://http-inputs-prd-p-xxxxx.splunkcloud.com:443/services/collector/event` and https://prd-p-xxxxx.splunkcloud.com:8088/services/collector/event respectively.

Labels (1)
Tags (1)
0 Karma
1 Solution

livehybrid
Contributor

The first request sounds almost right, but the token has Acknowledgement turned on so need to either turn that off or add a request channel (In curl this would be something like 

-H "X-Splunk-Request-Channel: FE0ECFAD-13D5-401B-847D-77883AD77131"

 

 

View solution in original post

livehybrid
Contributor

The first request sounds almost right, but the token has Acknowledgement turned on so need to either turn that off or add a request channel (In curl this would be something like 

-H "X-Splunk-Request-Channel: FE0ECFAD-13D5-401B-847D-77883AD77131"

 

 

View solution in original post

eltnegcoinprofi
Explorer

Thanks. Logging now works as expected. What happens when my trial period elapses? Does my instance get erased or will I have reduced logging functionalities?

0 Karma

livehybrid
Contributor

Unfortunately I think you will lose access to it. It may be worth speaking to the sales team to see if it can be extended?

Glad its working!

0 Karma

eltnegcoinprofi
Explorer

Thanks.🙂

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!