You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi,
Shouldn't the logs be formatted differently if "hec_endpoint_type" is set to Event instead of the default Raw ?
I got the following error when I set my configuration to Event
The data is not formatted correctly. To see how to properly format data for Raw or Event HEC endpoints, see Splunk Event Data (http://dev.splunk.com/view/event-collector/SP-CAAAE6P#data). HecServerErrorResponseException{serverRespObject=HecErrorResponseValueObject{text=Invalid data format, code=6, invalidEventNumber=0}, httpBodyAndStatus=HttpBodyAndStatus{statusCode=400, body={"text":"Invalid data format","code":6,"invalid-event-number":0}}, lifecycleType=EVENT_POST_NOT_OK, url=https://44.194.107.82:443, errorType=RECOVERABLE_DATA_ERROR, context=event_post}
Can anyone confirm it works with hec_endpoint_type set to Event ?
The text was updated successfully, but these errors were encountered:
Hi,
Shouldn't the logs be formatted differently if "hec_endpoint_type" is set to
Event
instead of the defaultRaw
?I got the following error when I set my configuration to
Event
Can anyone confirm it works with
hec_endpoint_type
set toEvent
?The text was updated successfully, but these errors were encountered: