If you've set up data forwarding via Splunk but events aren't being sent, here are a couple of things to check:
- The instance URL is incorrect. Double check the format:
- If you're using Splunk cloud, this is the format
https://input-<host>:8088
- if you're hosting Splunk yourself, this is the format:
https://http-inputs-<host>:8088
- See the full documentation here for more information
- If you're using Splunk cloud, this is the format
- Double check that in your Splunk configuration the HEC status is enabled. See this screenshot for what it should look like: