We are investigating how to create a Splunk log entry over the REST API via JavaScript. I'm posting the following event via the REST API:
curl -k -u user:password "https://tspl001:8089/services/receivers/simple?source=www&sourcetype=junk&index=angularjs_test" -d "2015-01-23 12:45:03 CST Hello there"
Here is the response:
<?xml version="1.0" encoding="UTF-8"?>
<response>
<messages>
<msg type="WARN">insufficient permission to access this resource</msg>
</messages>
</response>
I was told that my user has write privileges and that I'm using the correct sourcetype and index values. I cannot file any reference to what the "www" source is.
... View more