<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I can see data in logs but not in index for http event collector in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/I-can-see-data-in-logs-but-not-in-index-for-http-event-collector/m-p/394532#M6674</link>
    <description>&lt;P&gt;I can see http_event_collector_metrics.log logs under &lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/var/log/introspection/splunk/&lt;/P&gt;

&lt;P&gt;But splunk says latest event received was 2 days ago. Whats going wrong in http event collector as I cannot see data if I select index after 7th of may. Previous data is available&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:30:05 GMT</pubDate>
    <dc:creator>Amandeepsin</dc:creator>
    <dc:date>2020-09-29T19:30:05Z</dc:date>
    <item>
      <title>I can see data in logs but not in index for http event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/I-can-see-data-in-logs-but-not-in-index-for-http-event-collector/m-p/394532#M6674</link>
      <description>&lt;P&gt;I can see http_event_collector_metrics.log logs under &lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/var/log/introspection/splunk/&lt;/P&gt;

&lt;P&gt;But splunk says latest event received was 2 days ago. Whats going wrong in http event collector as I cannot see data if I select index after 7th of may. Previous data is available&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:30:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/I-can-see-data-in-logs-but-not-in-index-for-http-event-collector/m-p/394532#M6674</guid>
      <dc:creator>Amandeepsin</dc:creator>
      <dc:date>2020-09-29T19:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: I can see data in logs but not in index for http event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/I-can-see-data-in-logs-but-not-in-index-for-http-event-collector/m-p/394533#M6675</link>
      <description>&lt;P&gt;Hi @Amandeepsin &lt;/P&gt;

&lt;P&gt;The _introspection index data is splunk's internal metrics regarding HEC performance and connection.&lt;/P&gt;

&lt;P&gt;You need to check the own index into which the data is coming in.&lt;/P&gt;

&lt;P&gt;Here is the sample event.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4945i8BC0DCB2DC235122/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 21:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/I-can-see-data-in-logs-but-not-in-index-for-http-event-collector/m-p/394533#M6675</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2018-05-09T21:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: I can see data in logs but not in index for http event collector</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/I-can-see-data-in-logs-but-not-in-index-for-http-event-collector/m-p/394534#M6676</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Latest event to that own index which is mentioned in HEC source is 2 days ago. But in _introspection I can see events.&lt;/P&gt;

&lt;P&gt;Any comments!!&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 04:55:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/I-can-see-data-in-logs-but-not-in-index-for-http-event-collector/m-p/394534#M6676</guid>
      <dc:creator>Amandeepsin</dc:creator>
      <dc:date>2018-05-10T04:55:51Z</dc:date>
    </item>
  </channel>
</rss>

