The documentation mentions Splunk 6.x as a requirement but it only works with Splunk 6.4 or greater. The reason is that HEC was introduced in Splunk Enterprise 6.3.0 but only supports raw events starting with Splunk 6.4.0: http://dev.splunk.com/view/event-collector/SP-CAAAE8Y