All Apps and Add-ons

"Error: connect ECONNREFUSED 127.0.0.1:8000"

dhruv_admin
Loves-to-Learn

Dear community members,

I am running Splunk enterprise edition on my local windows system. Splunk web is up & running. I have created a Lambda function with a trigger cloudwatch logs where on every invocation it should send the cloudwatch logs to Splunk. But while invocation I am getting connection refused error. Please find the error below. Can someone help me to understand ?

ERROR Invoke Error

Labels (3)
0 Karma

PaulPanther
Builder

Which endpoint have you defined in your lambda function? localhost 127.0.0.1 is not an ip address that is reachable from an external source.

0 Karma

dhruv_admin
Loves-to-Learn

http://127.0.0.1:8000  as HEC variable

I have declared this variable and calling it in the function. Can you suggest how can I mitigate this issue ?

0 Karma

PaulPanther
Builder

127.0.0.1 is an internal ip address that you can't reach from any external source.  

localhost - Wikipedia

Furthermore Port 8000 is not the default HEC Port but the default web port. So if you haven't change the default port for the web ui you must use another (high) port for HEC. 

Set up and use HTTP Event Collector in Splunk Web - Splunk Documentation

 

0 Karma

dhruv_admin
Loves-to-Learn

Thanks, I will configure web ui with ssl certificate. Also HEC is running on port 8088

0 Karma

dhruv_admin
Loves-to-Learn

Hello Team,

I am using a blueprint lambda to process cloudwatch logs to splunk. I have configured HEC url & HEC token in Splunk we UI. Installed splunk in AWS linux server. But while invoking the lambda function getting above error.

HEC URL - http://54.67.83.247:8088/services/collector/raw

Whitelisted the IP in security group of ec2 instance where splunk is installed. Can anyone help me to fix this issue ?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...