Hello, I am using python to test sending events to splunk via hec, but I am getting the following error. this error is more of a python issue than splunk, I was wondering if any one had similar issue or have a suggestion. Thank you.
user_data_str looks like below
{
"GivenName": "MyName",
"sn": "MyLastN",
"UserPrincipalName": "MyName@client.com",
"sAMAccountName": "mysama",
"enabled": "[]",
"co": "United States",
"sourcetype": "my_hec_test",
"time": 9999999999.8921528
}
Header looks like below
{
'Authorization': 'Splunk abcdefgh-1234-ijkl-5678-mnopqrstu123456'
}
user_data_str include 3 users similar to above example
>>> print(range(len(user_data_str)))
range(0, 3)
>>> type(user_data_str)
<class 'list'>
>>> type(header)
<class 'dict'>
>>>
>>> requests.post('https://hec.splunkcloud.com/services/collector/event', headers = header, data = user_data_str, verify=False)
Traceback (most recent call last):
...
...
...
...
ValueError: too many values to unpack (expected 2)
... View more