Splunk Search

Query string method not working for HEC on Cloud

naiktej13
Engager

I have a splunk cloud stack which has HEC enabled on it and I am referring following page to send data via HEC:
http://dev.splunk.com/view/event-collector/SP-CAAAE7G

which have mentioned 3 ways:
1. HTTP Authentication
2. Basic authentication
3. Query string

Among them, 1 and 2 are working properly. But when I tried to send data via "Query string" it gives following Error:

{"text":"Query string authorization is not enabled","code":16}

The curl command I tried is as follow:
curl -k https://http-inputs-STACK_NAME.splunkcloud.com/services/collector/event?token=xxxxxxxx-xxxx-xxxx-xxx... -d '{"event": "hello world"}'

Any idea regarding How to enable the "Query string" in cloud stack?

0 Karma
1 Solution

hunters_splunk
Splunk Employee
Splunk Employee

Hi Naiktej13,

Seems that the allowQueryStringAuth has not been set to true in the HEC local stanza in your Cloud instance:
allowQueryStringAuth = [true|false]
For detailed information about his setting, see http://docs.splunk.com/Documentation/Splunk/6.6.0/Admin/Inputsconf#HTTP_Event_Collector_.28HEC.29_-_... .

Please contact your Cloud administrator to set allowQueryStringAuth to true to Enable sending authorization token with query string.

Hope it helps. Thanks!
Hunter

View solution in original post

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi Naiktej13,

Seems that the allowQueryStringAuth has not been set to true in the HEC local stanza in your Cloud instance:
allowQueryStringAuth = [true|false]
For detailed information about his setting, see http://docs.splunk.com/Documentation/Splunk/6.6.0/Admin/Inputsconf#HTTP_Event_Collector_.28HEC.29_-_... .

Please contact your Cloud administrator to set allowQueryStringAuth to true to Enable sending authorization token with query string.

Hope it helps. Thanks!
Hunter

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...