Splunk Enterprise

How to resolve HTTP event collector issue?

uagraw01
Motivator

Hello Splunkers!!

I want to setup HEC token mechnaism. But After send some events to Splunk by using curl script. I am getting an error "{"text":"The requested URL was not found on this server.","code":404}" . Please help me to fix this issue.

default port 8088 is setup

token is also setup

uagraw01_0-1680676796100.png

 

Thanks in advance

 

0 Karma
1 Solution

uagraw01
Motivator

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

View solution in original post

0 Karma

uagraw01
Motivator

@ITWhisperer I already tried but this, but not working

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Don't put a slash at the end of the URL.

0 Karma

uagraw01
Motivator

@PickleRick >curl -k http://127.0.0.1:8088/services/collector/event
{"text":"The requested URL was not found on this server.","code":404}
[IHT004][WALVAU-AGV-1][05-04-2023 8:21:11][C:\Users\viadmin]
>

I am getting the same error.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. So your Splunk server is running on Windows? And you did the HEC configuration how?

0 Karma

uagraw01
Motivator

@PickleRick I got the issue and fix it. 

workaround : I installed the curl agent and setup the required environmental variable and after that it works fine.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "curl agent"? And what environmental variable?

0 Karma

uagraw01
Motivator

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try /services/collector/event

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...