Use these tips to troubleshoot problems with HTTP.
Wait a Few Minutes
Wait a few minutes after sending an event to give it time to index and appear in the search results. It normally happens within seconds, but sometimes it can take longer.
Check Loggly Status
If Loggly isn’t seeing data check our status page to make sure we are indexing data and search is running. You should see green dots and “All Systems Operational”.
Check Customer Token
Make sure you replaced your customer token in the URL.
- TOKEN: your customer token from the source setup page
Test Sending data
You can POST an event to Loggly using our HTTP/S endpoint.
curl -H "content-type:text/plain" -d 'HelloWorld' http://logs-01.loggly.com/inputs/TOKEN/tag/http/
For sending multiline logs, you can use Bulk endpoint.
HTTP/S Bulk endpoint is great to send larger batches of line-separated events with faster transmission speed. You can send a maximum of 5MB per batch and up to 1MB per event. You can send plaintext or any type of automatically parsed log including JSON.
curl -H "content-type:text/plain" -d $'Hello\nWorld' http://logs-01.loggly.com/bulk/TOKEN/tag/bulk/
Content Type in Header
Check to make sure you are using the right contentType in header.
By default Loggly assumes the contentType of ‘application/x-www-form-urlencoded’ and will convert data to JSON automatically. You can set contentType in your header to ‘text/plain’ to leave your data alone and store it as regular text.
Check Response Status Code
You can check your HTTP response code from Status code
If you are trying to use the automatic verify feature, make sure you have the http tag in case of HTTP/S Event Endpoint and have the bulk tag in case of have HTTP/S Bulk Endpoint.
Check your File Size
If you get the error “413 Request Entity Too Large”, it means your file size is larger than the limit of 5MB. Please split your file into chunks less than 5MB, or curl the file one line at a time.
Check Data Transmission
Use netstat to verify HTTP has an established connection to Loggly. Specifically, check that Loggly can make a connection through your firewall on the proper port. It is 80 for HTTP, and 443 for HTTPS.
sudo netstat -taupn | grep 80
Use ping or telnet to verify if you can make an outbound connection to Loggly. If you can’t connect to it then might be a network or firewall issue.
telnet logs-01.loggly.com 80
Use tcpdump to verify data is being sent to Loggly. If you send your events in cleartext while tcpdump is running, you should be able to see them in the left hand column. You can also run tcpdump for port 80 or 443 depends on which connection you are using. It is 80 for HTTP, and 443 for HTTPS.
sudo tcpdump -A dst logs-01.loggly.com
Search Loggly for events with the tag as http over the past hour. It may take few minutes to index the event.
Still Not Working?
- Please search our community forum for more HTTP/S answers or post your own question.