<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Running into Errors when Configuring Log Streaming with Splunk
Administration
Okta Classic Engine
Okta Identity Engine
Overview

This article explains why the following errors may occur when configuring Log Streaming for a Splunk Cloud instance:

  • Name or service not known is not reachable
  • Host should be a domain without http or https
Applies To
  • Okta Log Streaming
  • Splunk Enterprise
  • Splunk Cloud
Cause

The "Name or service not known is not reachable" error occurs because Okta Log Streaming is only supported on Splunk Cloud instances. It does not work with Splunk Enterprise instances.

The Host should be a domain without http or https error occurs when a user includes "http" or "https" in the host value. It also occurs when the user includes the "http-inputs" subdomain. The "http-inputs-" subdomain is for the Splunk Cloud HTTP Event Collector (HEC) Uniform Resource Identifier (URI), not the actual Splunk domain name. The Okta system automatically accounts for this prefix. The correct host format is subdomain.splunkcloud.com.


The error message 

Solution
  1. When adding a Splunk log stream, ensure a Splunk Cloud instance is used, not a Splunk Enterprise instance.

  2. In the Host field, enter the domain for the Splunk Cloud instance without the "http" or "https" prefix.

  3. Remove the "http-inputs-" subdomain if it is present in the host value. The Okta system automatically accounts for this prefix.

  4. For additional information on HEC URI for Splunk Cloud Platform on Amazon Web Services (AWS), refer to the  Send data to HTTP Event Collector on Splunk Cloud Platform documentation.


Related References

Recommended content

Loading
Running into Errors when Configuring Log Streaming with Splunk