<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: An issue with the HTTP Event Collector (HEC) has been identified in Splunk 7.x in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458075#M79173</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;The latest maintenance release, 7.0.5, for Splunk Enterprise and Splunk UniversalForwarder are now available from the Download site. &lt;BR /&gt;
Please note as 7.0.5 is not the latest version, you can find it under the “Older Releases” section. &lt;/P&gt;

&lt;P&gt;Download: &lt;A href="https://www.splunk.com/en_us/download.html"&gt;https://www.splunk.com/en_us/download.html&lt;/A&gt; &lt;BR /&gt;
Known Issues: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Knownissues"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Knownissues&lt;/A&gt;&lt;BR /&gt;
Fixed Issues: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Fixedissues"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Fixedissues&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 28 Jul 2018 07:07:43 GMT</pubDate>
    <dc:creator>jmaher_splunk</dc:creator>
    <dc:date>2018-07-28T07:07:43Z</dc:date>
    <item>
      <title>An issue with the HTTP Event Collector (HEC) has been identified in Splunk 7.x</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458073#M79171</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt;&lt;BR /&gt;
After upgrading from Splunk Enterprise or Splunk Cloud 6.x to 7.x, customers are reporting a bug with HTTP Event Collector (HEC). As a result:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Some HEC events may not be getting ingested after the upgrade &lt;/LI&gt;
&lt;LI&gt;There may be a reduction in performance (indexing throughput) related to HEC events.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;STRONG&gt;What happened:&lt;/STRONG&gt;&lt;BR /&gt;
Splunk Enterprise and Splunk Cloud releases 7.x (“7.x”) include a limit on HTTP Event Collector (HEC) payloads of 512KB. This limit exists to prevent memory overuse. Post-7.0.x, HEC events with sizes exceeding 512KB are not resolved by the HEC parser, and may be dropped. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Which customers are impacted:&lt;/STRONG&gt;&lt;BR /&gt;
This issue may impact any customer meeting the following criteria:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Are on Splunk Enterprise or Splunk Cloud 7.x&lt;/LI&gt;
&lt;LI&gt;Use HEC &lt;/LI&gt;
&lt;LI&gt;Have a payload size above 512KB&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 26 Jul 2018 15:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458073#M79171</guid>
      <dc:creator>jmaher_splunk</dc:creator>
      <dc:date>2018-07-26T15:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: An issue with the HTTP Event Collector (HEC) has been identified in Splunk 7.x</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458074#M79172</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt; &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Splunk is working on a resolution to ensure the HEC module in Splunk Enterprise and Splunk Cloud 7.x is more tolerant of larger payloads by default, and we also plan to make the limit configurable to suit specific needs.&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Splunk Cloud customers that are potentially impacted, will be contacted over the next few weeks to schedule a maintenance window&lt;/LI&gt;
&lt;LI&gt;For Splunk Enterprise customers that are potentially impacted, this will be fixed in 7.0.5 (ETA July 27) and 7.1.3 (End of August). We will post to this thread as the maintenance releases are available.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 26 Jul 2018 21:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458074#M79172</guid>
      <dc:creator>jmaher_splunk</dc:creator>
      <dc:date>2018-07-26T21:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: An issue with the HTTP Event Collector (HEC) has been identified in Splunk 7.x</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458075#M79173</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;The latest maintenance release, 7.0.5, for Splunk Enterprise and Splunk UniversalForwarder are now available from the Download site. &lt;BR /&gt;
Please note as 7.0.5 is not the latest version, you can find it under the “Older Releases” section. &lt;/P&gt;

&lt;P&gt;Download: &lt;A href="https://www.splunk.com/en_us/download.html"&gt;https://www.splunk.com/en_us/download.html&lt;/A&gt; &lt;BR /&gt;
Known Issues: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Knownissues"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Knownissues&lt;/A&gt;&lt;BR /&gt;
Fixed Issues: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Fixedissues"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.5/ReleaseNotes/Fixedissues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jul 2018 07:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458075#M79173</guid>
      <dc:creator>jmaher_splunk</dc:creator>
      <dc:date>2018-07-28T07:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: An issue with the HTTP Event Collector (HEC) has been identified in Splunk 7.x</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458076#M79174</link>
      <description>&lt;P&gt;Is gzip content encoding header supported on HEC ? Would be useful while posting large payloads.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 05:53:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458076#M79174</guid>
      <dc:creator>shankern</dc:creator>
      <dc:date>2018-07-31T05:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: An issue with the HTTP Event Collector (HEC) has been identified in Splunk 7.x</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458077#M79175</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;and we also plan to make the limit configurable to suit specific needs&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;How do I configure this? I can't find anything in the docs or online&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 21:57:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/458077#M79175</guid>
      <dc:creator>adammike</dc:creator>
      <dc:date>2019-06-19T21:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: An issue with the HTTP Event Collector (HEC) has been identified in Splunk 7.x</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/515089#M87242</link>
      <description>&lt;PRE&gt;maxEventSize = &amp;lt;positive integer&amp;gt;[KB|MB|GB]
* The maximum size of a single HEC (HTTP Event Collector) event.&lt;/PRE&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Inputsconf&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 01:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/An-issue-with-the-HTTP-Event-Collector-HEC-has-been-identified/m-p/515089#M87242</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2020-08-20T01:33:52Z</dc:date>
    </item>
  </channel>
</rss>

