Panther HTTP
This output supports efficient batch loading of data into Panther's via HTTP Custom Log Format Source.
Prerequisites
Create a HTTP Custom Log Source, using the following information:
- In the left-hand navigation bar of your Panther Console, click Configure > Log Sources, and select 'Create New'
- Select custom log format and the HTTP source
- Source Name: (Name this whatever you want, e.g. Monad Connector)
- Schemas: (Leave empty, or can be defined per datatype being ingested from a Monad input)
- Auth method: Bearer
- Next to the Bearer Token Value field, press the "Refresh" button to generate a new Bearer Token Value. Copy this value, as it will be used in the configuration below.
- Click Setup
- While the HTTP source is being created, click the "Click here to preview your URL" button. Copy this value, as it will be used in the configuration below.
- If you missed this step, you can always find the HTTP Ingest URL in the Basic Info section of the Log Source. Once the HTTP source has been created, you can continue configuring the connector below.
Settings
| Setting | Type | Required | Default | Description |
|---|---|---|---|---|
| HTTP Ingest URL | string | Yes | - | The HTTP Source Ingest URL generated by Panther. |
Secrets
| Secret | Type | Required | Description |
|---|---|---|---|
| Bearer Token | string | Yes | The Bearer Authentication Token Value for the HTTP Source. |
Batching and Size Limits
Panther's HTTP source accepts at most 1 MB per request, including headers.
Panther rejects anything larger with 413 Request Entity Too Large.
Monad sends records to Panther in batches, with records separated by newlines. Each request holds up to 100 records and is kept under Panther's 1 MB limit. These batch settings are fixed for this output and are not configurable.
A single record larger than about 1 MB can't be delivered through Panther's HTTP source. If your records can exceed that size, use a transform to remove large fields before this output, or send the data to Panther through S3 instead.
Troubleshooting
413 Request Entity Too Large
Panther rejected a request because it was over the 1 MB limit. Monad keeps each batch under the limit, so this error means at least one record is larger than about 1 MB on its own. Reduce the size of those records before they reach this output, or send the data to Panther through S3 instead.