<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Event Collector do not completly index data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408337#M72395</link>
    <description>&lt;P&gt;Which Splunk version are you using?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jun 2018 17:36:16 GMT</pubDate>
    <dc:creator>amiftah</dc:creator>
    <dc:date>2018-06-26T17:36:16Z</dc:date>
    <item>
      <title>HTTP Event Collector do not completly index data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408333#M72391</link>
      <description>&lt;P&gt;While trying to index data using the HTTP Event Collector, I got some data loss, especially in the last row.&lt;BR /&gt;
Data format used is the following:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Multiple lines separated by &lt;STRONG&gt;CRLF&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;encode UTF-8&lt;/LI&gt;
&lt;LI&gt;Data's format : flat JSON&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Example:&lt;BR /&gt;
{"field1":1,"field2":2,"field3":"smth"} &lt;STRONG&gt;CRLF&lt;/STRONG&gt;&lt;BR /&gt;
{"field1":2,"field2":3,"field3":"smth"} &lt;STRONG&gt;CRLF&lt;/STRONG&gt;&lt;BR /&gt;
{"field1":3,"field2":4,"field3":"smth"}&lt;/P&gt;

&lt;P&gt;Anyone have an idea about this problem?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 10:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408333#M72391</guid>
      <dc:creator>nanapark</dc:creator>
      <dc:date>2018-06-25T10:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector do not completly index data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408334#M72392</link>
      <description>&lt;P&gt;Can you show your sourcetype in props.conf ?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 12:46:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408334#M72392</guid>
      <dc:creator>amiftah</dc:creator>
      <dc:date>2018-06-25T12:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector do not completly index data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408335#M72393</link>
      <description>&lt;P&gt;Unfortunately, I do not have access to the props.conf&lt;BR /&gt;
We found that special characters are making trouble for the HEC such as: double quotes “ or é or è ...&lt;BR /&gt;
Is there any solution to let the HEC accept those characters?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 13:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408335#M72393</guid>
      <dc:creator>nanapark</dc:creator>
      <dc:date>2018-06-26T13:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector do not completly index data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408336#M72394</link>
      <description>&lt;P&gt;I don't know if this can help. In indexed data I found this : sourcetype =  _json&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 13:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408336#M72394</guid>
      <dc:creator>nanapark</dc:creator>
      <dc:date>2018-06-26T13:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector do not completly index data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408337#M72395</link>
      <description>&lt;P&gt;Which Splunk version are you using?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 17:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408337#M72395</guid>
      <dc:creator>amiftah</dc:creator>
      <dc:date>2018-06-26T17:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector do not completly index data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408338#M72396</link>
      <description>&lt;P&gt;we are using splunk 6.5.3&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 07:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-do-not-completly-index-data/m-p/408338#M72396</guid>
      <dc:creator>nanapark</dc:creator>
      <dc:date>2018-06-27T07:47:20Z</dc:date>
    </item>
  </channel>
</rss>

