Splunk Enterprise

How to resolve HTTP event collector issue?

uagraw01
Builder

Hello Splunkers!!

I want to setup HEC token mechnaism. But After send some events to Splunk by using curl script. I am getting an error "{"text":"The requested URL was not found on this server.","code":404}" . Please help me to fix this issue.

default port 8088 is setup

token is also setup

uagraw01_0-1680676796100.png

 

Thanks in advance

 

Labels (1)
0 Karma
1 Solution

uagraw01
Builder

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

View solution in original post

0 Karma

uagraw01
Builder

@ITWhisperer I already tried but this, but not working

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Don't put a slash at the end of the URL.

0 Karma

uagraw01
Builder

@PickleRick >curl -k http://127.0.0.1:8088/services/collector/event
{"text":"The requested URL was not found on this server.","code":404}
[IHT004][WALVAU-AGV-1][05-04-2023 8:21:11][C:\Users\viadmin]
>

I am getting the same error.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. So your Splunk server is running on Windows? And you did the HEC configuration how?

0 Karma

uagraw01
Builder

@PickleRick I got the issue and fix it. 

workaround : I installed the curl agent and setup the required environmental variable and after that it works fine.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "curl agent"? And what environmental variable?

0 Karma

uagraw01
Builder

@PickleRick Actually i disabled ssl from http event collect and used “http” in place of “https”. Forget the curl

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try /services/collector/event

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...