- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-05-2024 08:36 AM
I have configured Splunk alert integration into Prisma cloud compute version Twistlock with the Splunk HEC URL, token, and cacert, but while doing the test alert it is throwing the below error, has anyone encountered such an issue, or any suggestions, please? The Splunk HEC URL is correct and up and running.
Error:
alert.go:1092 Failed to send client splunk alert, error: invalid response status. status: 404 Not Found, payload: "<doctype html<>html<head><meta http-equiv=\"content-type\" content=\"text/html: charset=UTF-8\"><title>404 Not Found</title></head></body><h1>Not Found</h1><p>The requested URL was not found on this server.</p></body></html>
02-06-2024 12:55 AM
It worked after adding /services/collector/event with the HEC URL
02-07-2024 07:30 AM
Hi @i.patel ,
Thanks for sharing the solution with us !
Kind regards,
Kim.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!