I found the issue. By default query strings are disabled for auth with HEC in Splunk Cloud. The documentation tells me to submit a ticket to an admin to get add allowQueryStringAuth=true to my token in the file: $SPLUNK_HOME/etc/apps/splunk_httpinput/local/inputs.conf. The problem is that I am using Splunk Cloud free to do testing for integration with Chef products and so I can't submit a ticket. Is there a way to do this without buying a support contract? (especially when you are just doing integration testing 🙂
... View more