Splunk Enterprise

How do I access my local Splunk enterprise to receive incoming webhooks from the internet?

s_palan
Loves-to-Learn Lots

I have installed free Splunk enterprise in my local system and It can be accessed via localhost:8000
I have also configured the webhook receiver in this instance to run at port 8088 via the HTTP event collector settings

I tried ngrok to expose localhost:8000 and localhost:8088 and use that public URL as a webhook listening server. But Splunk is not receiving any events. I can see my ngrok server being hit with the events but seems like it's not able to forward it over to splunk.

what am I doing wrong here? What's the right way to expose my localhost Splunk instance to start receiving these webhook events?

Thank you in advance for help!
Webhooks Input #splunklocalhost

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Are you sure you're using the webhook inputs app or did you just configure a HEC input?

2. Whatever that ngrok is - since you said that Splunk is listening on localhost - is it running on the same machine?

3. Did you verify if that ngrok is connecting to your Splunk instance and sending data?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...