<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App shows 200, but no data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467973#M57511</link>
    <description>&lt;P&gt;If you are sure that your data is coming into the Indexers, check the following (each of this will create a log in &lt;CODE&gt;index=_*&lt;/CODE&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1: If you are using an `index` value that is not defined:
1a: If you have `lastChanceIndex` defined, it will be there.
1b: If not, it will be dropped.
2: If your data is `malformed` then:
2a: If you have `malformedEventIndex` defined, it will be there.
2b: If not, it will be dropped.
3: If the date is too old, it will be dropped (see `MAX_DAYS_AGO`).
4: If the date is too far in the future, it will be dropped (see `MAX_DAYS_HENCE`).
5: If the date is interpreted incorrectly, you may be looking for it in the wrong place; it use to be that `All time` used `+Infinity` but in some versions of Splunk, splunk changed it to `now` but in the very latest 8.0.2 it is back to `+Infinity`".  In any case use the `Advanced` section of the `Timepicker` and use `0` for `Earliest` and `@d+20d` for `Latest`.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 11 Mar 2020 03:22:32 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2020-03-11T03:22:32Z</dc:date>
    <item>
      <title>App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467966#M57504</link>
      <description>&lt;P&gt;G'day!&lt;/P&gt;

&lt;P&gt;My Health Post app on my phone shows data upload succeeded and the logs show that it's getting 200's in response...but no data shows in my configured index per the HEC token (and the video).&lt;/P&gt;

&lt;P&gt;I've checked my token from outside (so no firewall issue). I turned off https because I'm not currently serving a cert on my HEC port, and I use a reverse proxy to get to the front-end UI.&lt;/P&gt;

&lt;P&gt;I'm open to suggestions, but I think at this point it may be how the iOS app translates my Splunk URL into a HEC endpoint...&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 03:35:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467966#M57504</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2020-02-06T03:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467967#M57505</link>
      <description>&lt;P&gt;I tested this with my reverse proxy config removed, local IPs, on the same local network as the instance last night, with the same result &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 22:22:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467967#M57505</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2020-02-06T22:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467968#M57506</link>
      <description>&lt;P&gt;What URL do you have configured on your handset app?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 10:47:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467968#M57506</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-07T10:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467969#M57507</link>
      <description>&lt;P&gt;I've tried the following (both http and https, with enabling and disabling SSL respectively in the HEC config):&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt; &lt;CODE&gt;internal IP&lt;/CODE&gt; while on the same wifi network with reverse proxy configuration removed.&lt;/LI&gt;
&lt;LI&gt; &lt;CODE&gt;external url&lt;/CODE&gt; which goes through nginx reverse proxy with both 8088 and 443 as ports&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The one thing I haven't done is reconfigure my port forwarding and reverse proxy config so that my external URL points directly at my Splunk instance.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 23:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467969#M57507</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2020-02-09T23:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467970#M57508</link>
      <description>&lt;P&gt;any more thoughts @nickhillscpl ?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 00:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467970#M57508</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2020-03-09T00:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467971#M57509</link>
      <description>&lt;P&gt;What actual Address are you using for the endpoint?&lt;BR /&gt;
It should be &lt;CODE&gt;yourhost:8088/services/collector/event&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 10:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467971#M57509</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-03-09T10:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467972#M57510</link>
      <description>&lt;P&gt;So the field in the app asks for the Splunk URL. Not the HEC endpoint. Since I use reverse proxy for the UI, I tried that. But I've also tried just putting the beginning bit of the HEC endpoint, assuming that it would add the /services/collector/event bit.&lt;BR /&gt;
When I put in the base URL (without the reverse proxy stuff) it says successful, but my DMC shows nothing, and there's no data &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 23:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467972#M57510</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2020-03-10T23:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467973#M57511</link>
      <description>&lt;P&gt;If you are sure that your data is coming into the Indexers, check the following (each of this will create a log in &lt;CODE&gt;index=_*&lt;/CODE&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1: If you are using an `index` value that is not defined:
1a: If you have `lastChanceIndex` defined, it will be there.
1b: If not, it will be dropped.
2: If your data is `malformed` then:
2a: If you have `malformedEventIndex` defined, it will be there.
2b: If not, it will be dropped.
3: If the date is too old, it will be dropped (see `MAX_DAYS_AGO`).
4: If the date is too far in the future, it will be dropped (see `MAX_DAYS_HENCE`).
5: If the date is interpreted incorrectly, you may be looking for it in the wrong place; it use to be that `All time` used `+Infinity` but in some versions of Splunk, splunk changed it to `now` but in the very latest 8.0.2 it is back to `+Infinity`".  In any case use the `Advanced` section of the `Timepicker` and use `0` for `Earliest` and `@d+20d` for `Latest`.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 11 Mar 2020 03:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467973#M57511</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-11T03:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467974#M57512</link>
      <description>&lt;P&gt;Even before any of this ^ wouldn't it show in the HEC Metrics that something is actually hitting?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 03:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467974#M57512</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2020-03-11T03:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: App shows 200, but no data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467975#M57513</link>
      <description>&lt;P&gt;Also I did an Real Time 1min window and sent backfill data. Nothing showed.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 03:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-shows-200-but-no-data/m-p/467975#M57513</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2020-03-11T03:25:34Z</dc:date>
    </item>
  </channel>
</rss>

