Splunk Enterprise

How to resolve HTTP event collector issue?

uagraw01
Motivator

Hello Splunkers!!

I want to setup HEC token mechnaism. But After send some events to Splunk by using curl script. I am getting an error "{"text":"The requested URL was not found on this server.","code":404}" . Please help me to fix this issue.

default port 8088 is setup

token is also setup

uagraw01_0-1680676796100.png

 

Thanks in advance

 

Labels (1)
0 Karma
1 Solution

uagraw01
Motivator

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

View solution in original post

0 Karma

uagraw01
Motivator

@ITWhisperer I already tried but this, but not working

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Don't put a slash at the end of the URL.

0 Karma

uagraw01
Motivator

@PickleRick >curl -k http://127.0.0.1:8088/services/collector/event
{"text":"The requested URL was not found on this server.","code":404}
[IHT004][WALVAU-AGV-1][05-04-2023 8:21:11][C:\Users\viadmin]
>

I am getting the same error.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. So your Splunk server is running on Windows? And you did the HEC configuration how?

0 Karma

uagraw01
Motivator

@PickleRick I got the issue and fix it. 

workaround : I installed the curl agent and setup the required environmental variable and after that it works fine.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "curl agent"? And what environmental variable?

0 Karma

uagraw01
Motivator

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try /services/collector/event

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...