<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is syslog-ng dropping events sent to SC4S's destination d_hec_fmt? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/709312#M117186</link>
    <description>&lt;P&gt;It is clean at startup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SC4S_ENV_CHECK_HEC: Splunk HEC connection test successful to index=sddc_internal for sourcetype=sc4s:fallback...&lt;BR /&gt;SC4S_ENV_CHECK_HEC: Splunk HEC connection test successful to index=sddc_internal for sourcetype=sc4s:events...&lt;BR /&gt;syslog-ng checking config&lt;BR /&gt;sc4s version=3.34.1&lt;BR /&gt;Configuring the health check port to: 8080&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [135] [INFO] Starting gunicorn 23.0.0&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [135] [INFO] Listening at: &lt;A href="http://0.0.0.0:8080" target="_blank"&gt;http://0.0.0.0:8080&lt;/A&gt; (135)&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [135] [INFO] Using worker: sync&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [138] [INFO] Booting worker with pid: 138&lt;BR /&gt;starting syslog-ng&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2025 13:48:38 GMT</pubDate>
    <dc:creator>tigerdice</dc:creator>
    <dc:date>2025-01-21T13:48:38Z</dc:date>
    <item>
      <title>Why is syslog-ng dropping events sent to SC4S's destination d_hec_fmt?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/579149#M102251</link>
      <description>&lt;P&gt;Searching _internal for source=sc4s shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;srlssydr01 syslog-ng 174 - [meta sequenceId="32595295"] Message(s) dropped while sending message to destination; driver='d_hec_fmt#0', worker_index='5', time_reopen='10', batch_size='19'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;srlssydr01 syslog-ng 174 - [meta sequenceId="32594764"] http: handled by response_action; action='drop', url='https://http-inputs-acme.splunkcloud.com:443/services/collector/event', status_code='400', driver='d_hec_fmt#0', location='root generator dest_hec:5:5'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 00:39:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/579149#M102251</guid>
      <dc:creator>gf13579</dc:creator>
      <dc:date>2021-12-23T00:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why is syslog-ng dropping events sent to SC4S's destination d_hec_fmt?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/579150#M102252</link>
      <description>&lt;P&gt;This can happen when you're trying to send to an index that doesn't exist. You can confirm this by turning on logging to d_hec_debug in /opt/sc4s/env_file and looking at the index-named folder list in /opt/sc4s/archive/debug and confirming all of those indexes exist.&lt;/P&gt;&lt;P&gt;Create the index or update splunk_metadata.csv to change the destination index for a given source key.&lt;/P&gt;&lt;P&gt;Thanks mbonsack in the sc4s community slack channel for the guidance. Posting here for visibility/googling.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 00:49:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/579150#M102252</guid>
      <dc:creator>gf13579</dc:creator>
      <dc:date>2021-12-23T00:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why is syslog-ng dropping events sent to SC4S's destination d_hec_fmt?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/709310#M117184</link>
      <description>&lt;P&gt;I am getting this all of the time and A the index exists and i can test it with curl and when sc4s starts it shows it is able to connect - it is annoying.&amp;nbsp; what else can i check it is not well documented.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 13:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/709310#M117184</guid>
      <dc:creator>tigerdice</dc:creator>
      <dc:date>2025-01-21T13:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why is syslog-ng dropping events sent to SC4S's destination d_hec_fmt?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/709311#M117185</link>
      <description>&lt;P class="lia-align-left"&gt;errors&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;syslog-ng&lt;/SPAN&gt; &lt;SPAN class=""&gt;149&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; [&lt;SPAN class=""&gt;meta&lt;/SPAN&gt; &lt;SPAN class=""&gt;sequenceId=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;100&lt;/SPAN&gt;"]&lt;SPAN class=""&gt;Server&lt;/SPAN&gt; &lt;SPAN class=""&gt;disconnected&lt;/SPAN&gt; &lt;SPAN class=""&gt;while&lt;/SPAN&gt; &lt;SPAN class=""&gt;preparing&lt;/SPAN&gt; &lt;SPAN class=""&gt;messages&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;sending&lt;/SPAN&gt;, &lt;SPAN class=""&gt;trying&lt;/SPAN&gt; &lt;SPAN class=""&gt;again&lt;/SPAN&gt;; &lt;SPAN class=""&gt;driver=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;d_hec_fmt_other#0&lt;/SPAN&gt;', &lt;SPAN class=""&gt;location=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;root&lt;/SPAN&gt; &lt;SPAN class=""&gt;generator&lt;/SPAN&gt; &lt;SPAN class=""&gt;dest_hec:5:5&lt;/SPAN&gt;', &lt;SPAN class=""&gt;worker_index=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;3&lt;/SPAN&gt;', &lt;SPAN class=""&gt;time_reopen=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;10&lt;/SPAN&gt;', &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;batch_size&lt;/SPAN&gt;=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;2'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="dev-ipz001-splunk05" href="https://rb-itoa-splunk-sh41.de.bosch.com:8000/en-US/app/sddc/search?q=search%20index%3Dsddc_internal%20host%3Ddev-ipz001-splunk05&amp;amp;display.page.search.mode=fast&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-24h&amp;amp;latest=now&amp;amp;sid=1737466933.3797506#" target="_blank" rel="noopener"&gt;dev-ipz001-splunk05&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="sc4s" href="https://rb-itoa-splunk-sh41.de.bosch.com:8000/en-US/app/sddc/search?q=search%20index%3Dsddc_internal%20host%3Ddev-ipz001-splunk05&amp;amp;display.page.search.mode=fast&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-24h&amp;amp;latest=now&amp;amp;sid=1737466933.3797506#" target="_blank" rel="noopener"&gt;sc4s&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="sc4s:events" href="https://rb-itoa-splunk-sh41.de.bosch.com:8000/en-US/app/sddc/search?q=search%20index%3Dsddc_internal%20host%3Ddev-ipz001-splunk05&amp;amp;display.page.search.mode=fast&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-24h&amp;amp;latest=now&amp;amp;sid=1737466933.3797506#" target="_blank" rel="noopener"&gt;sc4s:events&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;1/21/25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2:41:42.705 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;syslog-ng&lt;/SPAN&gt; &lt;SPAN class=""&gt;149&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; [&lt;SPAN class=""&gt;meta&lt;/SPAN&gt; &lt;SPAN class=""&gt;sequenceId=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;100&lt;/SPAN&gt;"]&lt;SPAN class=""&gt;http:&lt;/SPAN&gt; &lt;SPAN class=""&gt;error&lt;/SPAN&gt; &lt;SPAN class=""&gt;sending&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;request&lt;/SPAN&gt;; &lt;SPAN class=""&gt;url=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;&lt;A href="https://somehost.com:3001/services/collector/event" target="_blank" rel="noopener"&gt;https://somehost.com:3001/services/collector/event&lt;/A&gt;&lt;/SPAN&gt;', &lt;SPAN class=""&gt;error=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;sending&lt;/SPAN&gt; &lt;SPAN class=""&gt;data&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;peer&lt;/SPAN&gt;', &lt;SPAN class=""&gt;worker_index=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;3&lt;/SPAN&gt;', &lt;SPAN class=""&gt;driver=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;d_hec_fmt_other#0&lt;/SPAN&gt;', &lt;SPAN class=""&gt;location=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;root&lt;/SPAN&gt; &lt;SPAN class=""&gt;generator&lt;/SPAN&gt; &lt;SPAN class=""&gt;dest_hec:5:5'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="dev-ipz001-splunk05" href="https://rb-itoa-splunk-sh41.de.bosch.com:8000/en-US/app/sddc/search?q=search%20index%3Dsddc_internal%20host%3Ddev-ipz001-splunk05&amp;amp;display.page.search.mode=fast&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-24h&amp;amp;latest=now&amp;amp;sid=1737466933.3797506#" target="_blank" rel="noopener"&gt;splunk05&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="sc4s" href="https://rb-itoa-splunk-sh41.de.bosch.com:8000/en-US/app/sddc/search?q=search%20index%3Dsddc_internal%20host%3Ddev-ipz001-splunk05&amp;amp;display.page.search.mode=fast&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-24h&amp;amp;latest=now&amp;amp;sid=1737466933.3797506#" target="_blank" rel="noopener"&gt;sc4s&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="sc4s:events" href="https://rb-itoa-splunk-sh41.de.bosch.com:8000/en-US/app/sddc/search?q=search%20index%3Dsddc_internal%20host%3Ddev-ipz001-splunk05&amp;amp;display.page.search.mode=fast&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-24h&amp;amp;latest=now&amp;amp;sid=1737466933.3797506#" target="_blank" rel="noopener"&gt;sc4s:events&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 21 Jan 2025 13:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/709311#M117185</guid>
      <dc:creator>tigerdice</dc:creator>
      <dc:date>2025-01-21T13:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is syslog-ng dropping events sent to SC4S's destination d_hec_fmt?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/709312#M117186</link>
      <description>&lt;P&gt;It is clean at startup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SC4S_ENV_CHECK_HEC: Splunk HEC connection test successful to index=sddc_internal for sourcetype=sc4s:fallback...&lt;BR /&gt;SC4S_ENV_CHECK_HEC: Splunk HEC connection test successful to index=sddc_internal for sourcetype=sc4s:events...&lt;BR /&gt;syslog-ng checking config&lt;BR /&gt;sc4s version=3.34.1&lt;BR /&gt;Configuring the health check port to: 8080&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [135] [INFO] Starting gunicorn 23.0.0&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [135] [INFO] Listening at: &lt;A href="http://0.0.0.0:8080" target="_blank"&gt;http://0.0.0.0:8080&lt;/A&gt; (135)&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [135] [INFO] Using worker: sync&lt;BR /&gt;[2025-01-21 13:36:54 +0000] [138] [INFO] Booting worker with pid: 138&lt;BR /&gt;starting syslog-ng&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 13:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-syslog-ng-dropping-events-sent-to-SC4S-s-destination-d/m-p/709312#M117186</guid>
      <dc:creator>tigerdice</dc:creator>
      <dc:date>2025-01-21T13:48:38Z</dc:date>
    </item>
  </channel>
</rss>

