<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HEC random issue in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/HEC-random-issue/m-p/417039#M7272</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm using HEC to send data to our splunk cloud instance in _json format. Currently I have 2 pods - 1 HEC - 2 indexes architecture.&lt;BR /&gt;
I do a "transaction" and I have 3 splunk JSON events going one to indexA and the 2 others to indexB.&lt;/P&gt;

&lt;P&gt;Randomly I'm getting an error &lt;BR /&gt;
{"type":"INTERNAL","description":"error during post to splunk for tenantId=monitoring err=StatusCodeError: 400 - {\\"text\\":\\"Incorrect index\\",\\"code\\":7,\\"invalid-event-number\\":1}"},&lt;/P&gt;

&lt;P&gt;However indexes are correct as I see events on them. For example in the log sample above I have only one event in indexB (Where I should have 2) and one in indexA.  Sometimes is one event failing, sometimes 2, and sometimes is one index and sometimes is the other.&lt;/P&gt;

&lt;P&gt;In introspection index I see parse error is 1, however I don't know where I can see a more detailed explanation. &lt;BR /&gt;
I've already check HTTP collector troubleshooting page, again I'm in splunk cloud with no access to config files, so I'm kind of block.&lt;/P&gt;

&lt;P&gt;Can someone help me to either to know how to get more information or share if you've faced a similar issue?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2019 11:07:37 GMT</pubDate>
    <dc:creator>smalonso</dc:creator>
    <dc:date>2019-06-10T11:07:37Z</dc:date>
    <item>
      <title>HEC random issue</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/HEC-random-issue/m-p/417039#M7272</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm using HEC to send data to our splunk cloud instance in _json format. Currently I have 2 pods - 1 HEC - 2 indexes architecture.&lt;BR /&gt;
I do a "transaction" and I have 3 splunk JSON events going one to indexA and the 2 others to indexB.&lt;/P&gt;

&lt;P&gt;Randomly I'm getting an error &lt;BR /&gt;
{"type":"INTERNAL","description":"error during post to splunk for tenantId=monitoring err=StatusCodeError: 400 - {\\"text\\":\\"Incorrect index\\",\\"code\\":7,\\"invalid-event-number\\":1}"},&lt;/P&gt;

&lt;P&gt;However indexes are correct as I see events on them. For example in the log sample above I have only one event in indexB (Where I should have 2) and one in indexA.  Sometimes is one event failing, sometimes 2, and sometimes is one index and sometimes is the other.&lt;/P&gt;

&lt;P&gt;In introspection index I see parse error is 1, however I don't know where I can see a more detailed explanation. &lt;BR /&gt;
I've already check HTTP collector troubleshooting page, again I'm in splunk cloud with no access to config files, so I'm kind of block.&lt;/P&gt;

&lt;P&gt;Can someone help me to either to know how to get more information or share if you've faced a similar issue?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 11:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/HEC-random-issue/m-p/417039#M7272</guid>
      <dc:creator>smalonso</dc:creator>
      <dc:date>2019-06-10T11:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: HEC random issue</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/HEC-random-issue/m-p/417040#M7273</link>
      <description>&lt;P&gt;Hello, for anyone interested and update on this issue:&lt;/P&gt;

&lt;P&gt;The problem happens when using 1 server - 2 HEC - 4 indexes (2 for each HEC) &lt;BR /&gt;
I made a few tests such as&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;2 pod   - 1 HEC - 4 indexes&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;2 pods - 2 HEC - 2 indexes (Only one index per HEC)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In both cases the issue is not present. I couldn't find the reason yet. &lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 09:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/HEC-random-issue/m-p/417040#M7273</guid>
      <dc:creator>smalonso</dc:creator>
      <dc:date>2019-06-12T09:59:49Z</dc:date>
    </item>
  </channel>
</rss>

