I’m attempting to send Cribl Stream notifications for one of my sources via HEC to Splunk. I’ve configured the Webhook target with the url to my Splunk instance’s HEC endpoint with the token in the url. However, I see Status Codes of 400 and the following message in Stream: text:Query string authorization is not enabled. How do I properly configure the notification target to send via HEC to Splunk?
Question
How to configure Splunk HEC as a Notification Webhook Target
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
