I defined a new HOC and I have a valid token now. now I'm trying to add some data using the HTTP Event Collector options. I added local CSV file data to the Splunk Cloud from the 'Add data -> Upload' option. Hello, world!'įor example: curl -k "" -d '1, 2, 3. Need help to send data Splunk Cloud using HEC. Initial Configuration All you need to do before running sc4s with Ansible is providing envfile. All you need to do now is provide a host on which you want to run SC4S and basic configuration (Splunk endpoint, HEC token, TLS configuration, etc.). HEC token can then be specified as a query string in the URL in the format: ?token=įor example: curl -k "" -d '1, 2, 3. SC4S installation can now be automated with Ansible. Support for a toggle in Splunk Web for this setting is planned for a future release. Save and close the nf file and restart Splunk service to reload configuration.įor Splunk Cloud, you must open a Splunk Support ticket to set allowQueryStringAuth to true.Within the stanza for each token that needs to enable query string authentication, add the following setting (or change the existing setting, if applicable): allowQueryStringAuth = true.Tokens are listed by name in this file, in the form.
0 Comments
Leave a Reply. |