If the event collector token is functioning correctly, you should receive a response similar to the following:
{"text":"Success","code":0}If you do not receive a successful response, you may need to modify your Splunk instance URL in one of the following ways:
- Splunk Enterprise —Add
inputs-to the beginning of your instance URL:https://inputs-your-splunk-instance:8088/services/collector/raw - Splunk Cloud —Add
http-inputs-to the beginning of your instance URL:https://http-inputs-your-splunk-instance:433/services/collector/raw