Splunk Enterprise

How to resolve HTTP event collector issue?

uagraw01
Motivator

Hello Splunkers!!

I want to setup HEC token mechnaism. But After send some events to Splunk by using curl script. I am getting an error "{"text":"The requested URL was not found on this server.","code":404}" . Please help me to fix this issue.

default port 8088 is setup

token is also setup

uagraw01_0-1680676796100.png

 

Thanks in advance

 

Labels (1)
0 Karma
1 Solution

uagraw01
Motivator

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

View solution in original post

0 Karma

uagraw01
Motivator

@ITWhisperer I already tried but this, but not working

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Don't put a slash at the end of the URL.

0 Karma

uagraw01
Motivator

@PickleRick >curl -k http://127.0.0.1:8088/services/collector/event
{"text":"The requested URL was not found on this server.","code":404}
[IHT004][WALVAU-AGV-1][05-04-2023 8:21:11][C:\Users\viadmin]
>

I am getting the same error.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. So your Splunk server is running on Windows? And you did the HEC configuration how?

0 Karma

uagraw01
Motivator

@PickleRick I got the issue and fix it. 

workaround : I installed the curl agent and setup the required environmental variable and after that it works fine.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "curl agent"? And what environmental variable?

0 Karma

uagraw01
Motivator

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try /services/collector/event

0 Karma
Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...