<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: http event data is not received at index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749952#M119151</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311712"&gt;@palyogit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check this documentation and try to send an sample events to HEC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/http-event-collector-examples" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/http-event-collector-examples&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/use-curl-to-manage-http-event-collector-tokens-events-and-services" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/use-curl-to-manage-http-event-collector-tokens-events-and-services&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jul 2025 05:35:58 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-07-17T05:35:58Z</dc:date>
    <item>
      <title>http event data is not received at index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749948#M119148</link>
      <description>&lt;P class="lia-align-left"&gt;http event data is not received at index&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;though in the log it says&amp;nbsp;HttpInputDataHandler - handled token name=xyz&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;How do i debug this i checked splunkd.log and could not find anything fishy&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;07-16-2025 16:14:39.809 +0800 DEBUG HttpInputDataHandler - handled token name=embedded, channel=n/a, source_IP=x.y.z.a, reply=0, events_processed=1, http_input_body_size=10338, parsing_err="", body_chunk="{"action": "queued", "workflow_job": {"id": 46075907488, "run_id": 16313804135, "workflow_name": "linux-ci-pipeline", "head_branch": "dts_changes", "run_url": "&lt;A href="https://api.github.com/repos/org/repo-name/actions/runs/16313804135" target="_blank" rel="noopener"&gt;https://api.github.com/repos/org/repo-name/actions/runs/16313804135&lt;/A&gt;", "run_attempt": 1, "node_id": "CR_kwDOHHhjyM8AAAAKulaNoA", "head_sha": "9fd419d2fcd5fc775c4b61a5392133630d5763b8", "url": "&lt;A href="https://api.github.com/repos/org/repo-name/actions/job" target="_blank" rel="noopener"&gt;https://api.github.com/repos/org/repo-name/actions/job&lt;/A&gt;"&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG UTF8Processor - Done key received for: source::/infrastructure/da_infra/splunk/tarball/splunk_instance/splunk/var/log/splunk/metrics.log|host::baip052|splunkd|2532&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 INFO UTF8Processor - Converting using CHARSET="UTF-8" for conf "source::http:embedded|host::10.244.215.89:8088|httpevent|"&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Interpolated to metrics_log_clone::s&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Extracted metrics_log_clone::s&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 INFO LineBreakingProcessor - Using truncation length 10000 for conf "source::http:embedded|host::10.244.215.89:8088|httpevent|"&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Interpolated to _metrics&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 INFO LineBreakingProcessor - LB_CHUNK_BREAKER uses truncation length 2000000 for conf "source::http:embedded|host::10.244.215.89:8088|httpevent|"&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 INFO LineBreakingProcessor - Using lookbehind 100 for conf "source::http:embedded|host::10.244.215.89:8088|httpevent|"&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Extracted _metrics&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 WARN LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exceeded with a line length &amp;gt;= 10338 - data_source="http:embedded", data_host="10.244.215.89:8088", data_sourcetype="httpevent"&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Interpolated to group::pipeline&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Extracted group::pipeline&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Interpolated to name::dev-null&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Extracted name::dev-null&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG regexExtractionProcessor - RegexExtractor: Interpolated to processor::nullqueue&lt;BR /&gt;07-16-2025 16:14:39.809 +0800 DEBUG UTF8Processor - Done key received for: source::http:embedded|host::10.244.215.89:8088|httpevent|&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 04:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749948#M119148</guid>
      <dc:creator>palyogit</dc:creator>
      <dc:date>2025-07-17T04:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: http event data is not received at index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749951#M119150</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311712"&gt;@palyogit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure that your HEC input includes valid index= . Missing or mis-typed values cause Splunk to drop data.&lt;/P&gt;&lt;PRE&gt;HttpInputDataHandler - handled token name=embedded … events_processed=1 … Truncating line because limit of 10000 bytes …&lt;/PRE&gt;&lt;P&gt;it means Splunk HEC received the event, parsed it, but &lt;STRONG&gt;truncated the line at ~10 kB&lt;/STRONG&gt;, which likely leads to it being dropped&amp;nbsp; before indexing&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 05:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749951#M119150</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-07-17T05:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: http event data is not received at index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749952#M119151</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311712"&gt;@palyogit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check this documentation and try to send an sample events to HEC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/http-event-collector-examples" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/http-event-collector-examples&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/use-curl-to-manage-http-event-collector-tokens-events-and-services" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/get-data-with-http-event-collector/use-curl-to-manage-http-event-collector-tokens-events-and-services&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 05:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749952#M119151</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-07-17T05:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: http event data is not received at index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749955#M119153</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311712"&gt;@palyogit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two main things are highlighting in the log&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;WARN LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exceeded...
regexExtractionProcessor - Interpolated to processor::nullqueue&lt;/LI-CODE&gt;&lt;P&gt;Looks like your truncating limit is hitting and discarding the event.&lt;/P&gt;&lt;P&gt;Increase TRUNCATE Limit in props.conf and test again.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Eg:
[httpevent]
TRUNCATE = 20000&lt;/LI-CODE&gt;&lt;P&gt;Also you can refer below,&lt;/P&gt;&lt;P&gt;#&lt;A href="https://help.splunk.com/en/data-management/collect-http-event-data/use-hec-in-splunk-enterprise/http-event-collector-example" target="_blank"&gt;https://help.splunk.com/en/data-management/collect-http-event-data/use-hec-in-splunk-enterprise/http-event-collector-example&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 06:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749955#M119153</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-17T06:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: http event data is not received at index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749962#M119154</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311712"&gt;@palyogit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at this I think there are two issues. Im not entirely sure they are related as others have suggested, because you would usually expect an event to be dropped if it hits the TRUNCATE limit, you would just be left with the first 10,000 characters.&lt;/P&gt;&lt;P&gt;The first thing to do is increase that 10000 limit - are you expecting the events to be this large?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# props.conf #
[httpevent]
# Increase to a number bigger than the events which are being truncated.
TRUNCATE=50000 &lt;/LI-CODE&gt;&lt;P&gt;The other log line which caught my eye is:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;RegexExtractor: Interpolated to processor::nullqueue&lt;/LI-CODE&gt;&lt;P&gt;especially because you are missing the events entirely. Do you have any props which are setting the nullqueue? Please can you do a btool and share hte output?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME/bin/splunk cmd btool props list --debug httpevent&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 06:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/749962#M119154</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-17T06:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: http event data is not received at index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/750159#M119189</link>
      <description>&lt;P&gt;Thanks everyone for your response. The issue was due to&amp;nbsp;DATETIME_CONFIG setting in&amp;nbsp; props.conf .It was set to custom value which was causing packets to drop. setting it&amp;nbsp;DATETIME_CONFIG = NONE helped resolve the issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 06:41:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/http-event-data-is-not-received-at-index/m-p/750159#M119189</guid>
      <dc:creator>palyogit</dc:creator>
      <dc:date>2025-07-21T06:41:06Z</dc:date>
    </item>
  </channel>
</rss>

