<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HEC Events not indexing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569327#M100968</link>
    <description>&lt;P&gt;I'm learning how to use the HTTP Event collector, but no events ever show up in search. I have the inputs enabled and my token set up as shown:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bsheppard8_0-1633091014316.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16244i0DF7CF69F18B40CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bsheppard8_0-1633091014316.png" alt="bsheppard8_0-1633091014316.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I run the command 'curl -k &lt;A href="https://community.splunk.com/" target="_blank"&gt;http://&amp;lt;instance-host&amp;gt;:8088/services/collector&lt;/A&gt;&amp;nbsp;-H "Authorization:Splunk &lt;SPAN&gt;4f99809e-55d3-4677-b418-c0be66693311" -d "{\"sourcetype\": \"trial\", \"event\":\"Hello World!\"}"'&amp;nbsp;&lt;/SPAN&gt;in my command prompt, I get back {"text": "Success", "code": 0}.&lt;/P&gt;&lt;P&gt;I followed along with the tutorial on this site here:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=qROXrFGqWAU" target="_blank"&gt;https://www.youtube.com/watch?v=qROXrFGqWAU&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I've also tried changing the sourcetype to json_no_timestamp, but this didn't work either.&lt;/P&gt;&lt;P&gt;I'm confident that I've set up everything correctly, but nothing seems to be working. Is there a fix for this? Because I'm trying to do the same with collectd metrics.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Oct 2021 12:31:58 GMT</pubDate>
    <dc:creator>bsheppard8</dc:creator>
    <dc:date>2021-10-01T12:31:58Z</dc:date>
    <item>
      <title>HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569327#M100968</link>
      <description>&lt;P&gt;I'm learning how to use the HTTP Event collector, but no events ever show up in search. I have the inputs enabled and my token set up as shown:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bsheppard8_0-1633091014316.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16244i0DF7CF69F18B40CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bsheppard8_0-1633091014316.png" alt="bsheppard8_0-1633091014316.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I run the command 'curl -k &lt;A href="https://community.splunk.com/" target="_blank"&gt;http://&amp;lt;instance-host&amp;gt;:8088/services/collector&lt;/A&gt;&amp;nbsp;-H "Authorization:Splunk &lt;SPAN&gt;4f99809e-55d3-4677-b418-c0be66693311" -d "{\"sourcetype\": \"trial\", \"event\":\"Hello World!\"}"'&amp;nbsp;&lt;/SPAN&gt;in my command prompt, I get back {"text": "Success", "code": 0}.&lt;/P&gt;&lt;P&gt;I followed along with the tutorial on this site here:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=qROXrFGqWAU" target="_blank"&gt;https://www.youtube.com/watch?v=qROXrFGqWAU&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I've also tried changing the sourcetype to json_no_timestamp, but this didn't work either.&lt;/P&gt;&lt;P&gt;I'm confident that I've set up everything correctly, but nothing seems to be working. Is there a fix for this? Because I'm trying to do the same with collectd metrics.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 12:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569327#M100968</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-01T12:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569335#M100970</link>
      <description>&lt;P&gt;Is it some lab installation? Do you have high ingest ratio or rather "un-busy" system?&lt;/P&gt;&lt;P&gt;If it's a small installation, just do a realtime search for "index=*" and see whether (and where) your events appear. Don't try this on a busy server!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 13:02:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569335#M100970</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-01T13:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569337#M100971</link>
      <description>I set it to an index that doesn't have any events so that I'd know right away that they're populating. And I have tried index=*, but I still don't see the test message I sent.</description>
      <pubDate>Fri, 01 Oct 2021 13:18:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569337#M100971</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-01T13:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569343#M100972</link>
      <description>&lt;P&gt;Check your /opt/splunk/var/log/splunkd.log for "HEC".&lt;/P&gt;&lt;P&gt;Typical error is that you send events to a non-existent index. But unless you have the destination index set to "Default" it's rather unlikely if you configure the input with GUI.&lt;/P&gt;&lt;P&gt;Anyway, add an "index" field to your HEC request and check if it works.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 14:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569343#M100972</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-01T14:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569359#M100974</link>
      <description>The current index for the token is "history", and the default index is "main". I'm not seeing a log labelled "splunkd" for this instance, but are there configurations for the indices I could try?</description>
      <pubDate>Fri, 01 Oct 2021 15:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569359#M100974</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-01T15:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569379#M100976</link>
      <description>Update: I was able to find the log, but I'm not seeing anything about HEC so far.</description>
      <pubDate>Fri, 01 Oct 2021 17:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569379#M100976</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-01T17:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569385#M100978</link>
      <description>&lt;P&gt;But have you tried adding a "index" field to explicitly specify an index?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 18:11:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569385#M100978</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-01T18:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569388#M100980</link>
      <description>Are you referring to the token? If so, yes, it's currently set to "history". I included a picture of the settings. If you mean something else, then no.</description>
      <pubDate>Fri, 01 Oct 2021 18:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569388#M100980</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-01T18:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569390#M100981</link>
      <description>&lt;P&gt;No. I mean instead of&lt;/P&gt;&lt;PRE&gt;curl -k &lt;A href="https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569388" target="_blank" rel="nofollow noopener noreferrer"&gt;http://&amp;lt;instance-host&amp;gt;:8088/services/collector&lt;/A&gt;&amp;nbsp;-H "Authorization:Splunk &lt;SPAN&gt;4f99809e-55d3-4677-b418-c0be66693311" -d "{\"sourcetype\": \"trial\", \"event\":\"Hello World!\"}"&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;do&lt;/P&gt;&lt;PRE&gt;curl -k &lt;A href="https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569388" target="_blank" rel="nofollow noopener noreferrer"&gt;http://&amp;lt;instance-host&amp;gt;:8088/services/collector&lt;/A&gt;&amp;nbsp;-H "Authorization:Splunk &lt;SPAN&gt;4f99809e-55d3-4677-b418-c0be66693311" -d "{\"sourcetype\": \"trial\", \"event\":\"Hello World!\",\"index\":\"history\"}"&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 18:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569390#M100981</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-01T18:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569391#M100982</link>
      <description>Yeah, I tried this too just now and searched for a matching index. Still nothing.</description>
      <pubDate>Fri, 01 Oct 2021 18:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569391#M100982</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-01T18:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569409#M100983</link>
      <description>&lt;P&gt;Hi. As an experiment I used a deliberately bad token and found this error.&amp;nbsp; Try searching for errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=myindexers* log_level=ERROR component=HttpInputDataHandler

10-01-2021 23:00:15.133 +0000 ERROR HttpInputDataHandler - Failed processing http input, token name=n/a, channel=n/a, source_IP=1.2.3.4, reply=4, events_processed=0, http_input_body_size=39, parsing_err=""&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 23:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569409#M100983</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-10-01T23:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569424#M100985</link>
      <description>&lt;P&gt;I noticed you're using /collector endpoint. Try /collector/event endpoint. I'm not sure - to be fully honest - what's the difference exactly, but there are two separate endpoints, so...&lt;/P&gt;</description>
      <pubDate>Sat, 02 Oct 2021 06:25:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569424#M100985</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-02T06:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569533#M100997</link>
      <description>I tried this as well, but I'm still not seeing any events. Is it possible that something in my instance isn't configured properly? Is there something I need to configure in order for an event to be created?</description>
      <pubDate>Mon, 04 Oct 2021 11:27:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569533#M100997</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-04T11:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569535#M100998</link>
      <description>I tried using the search field by field. I was only able to find events with the index "_internal". Sadly, I wasn't able to find any events linked to events failing to process or issues with the HttpInputDataHandler. I don't see any issues in the splunkd log, either.</description>
      <pubDate>Mon, 04 Oct 2021 11:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569535#M100998</guid>
      <dc:creator>bsheppard8</dc:creator>
      <dc:date>2021-10-04T11:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Events not indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569904#M101035</link>
      <description>&lt;P&gt;That's all interesting because... it should work but doesn't.&lt;/P&gt;&lt;P&gt;On HEC request you should either get an error (if you have bad token or try to write into an index you don't have permissions for) or the event should get accepted. You're saying that it does get accepted.&lt;/P&gt;&lt;P&gt;So it should either get written into an index or splunk itself should log something into logs that tells you what's preventing it from indexing the event (like trying to write to a non-existent index).&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 14:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Events-not-indexing/m-p/569904#M101035</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-06T14:32:11Z</dc:date>
    </item>
  </channel>
</rss>

