<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Index has empty data when using HEC in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/527852#M89006</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need an urgent help.&lt;/P&gt;&lt;P&gt;I created HEC data inputs. I did follow these guidelines.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/HECExamples" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/HECExamples&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/UsetheHTTPEventCollector" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/UsetheHTTPEventCollector&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The test was success and I'm able to get&amp;nbsp;&lt;/P&gt;&lt;DIV class="samplecode"&gt;&lt;PRE&gt;{"text": "Success", "code": 0}&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;However, the index was still empty which I'm expecting it should contains the message data.&lt;/P&gt;&lt;P&gt;What would be the reason?&lt;/P&gt;&lt;P&gt;Our Splunk Deployment is like below&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1 Searchead Instance&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2 Indexer Instance&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;4 Forwarder Instance.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created the HEC on Searchead via GUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help to advice and thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 07:28:37 GMT</pubDate>
    <dc:creator>malikperang</dc:creator>
    <dc:date>2020-11-04T07:28:37Z</dc:date>
    <item>
      <title>Index has empty data when using HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/527852#M89006</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need an urgent help.&lt;/P&gt;&lt;P&gt;I created HEC data inputs. I did follow these guidelines.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/HECExamples" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/HECExamples&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/UsetheHTTPEventCollector" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/UsetheHTTPEventCollector&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The test was success and I'm able to get&amp;nbsp;&lt;/P&gt;&lt;DIV class="samplecode"&gt;&lt;PRE&gt;{"text": "Success", "code": 0}&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;However, the index was still empty which I'm expecting it should contains the message data.&lt;/P&gt;&lt;P&gt;What would be the reason?&lt;/P&gt;&lt;P&gt;Our Splunk Deployment is like below&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1 Searchead Instance&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2 Indexer Instance&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;4 Forwarder Instance.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created the HEC on Searchead via GUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help to advice and thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 07:28:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/527852#M89006</guid>
      <dc:creator>malikperang</dc:creator>
      <dc:date>2020-11-04T07:28:37Z</dc:date>
    </item>
    <item>
      <title>Index has empty data when using HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/527943#M89018</link>
      <description>&lt;P&gt;HEC should be installed on indexers rather than search heads.&amp;nbsp; HEC on SH may work if data is forwarded to the indexers, but I've never seen it done that way.&lt;/P&gt;&lt;P&gt;How are you looking for the data?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 14:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/527943#M89018</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-04T14:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: Index has empty data when using HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/528055#M89025</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;I just create the HEC on Indexer.&amp;nbsp; Success on sending data via HTTP collector but however, when I go to Monitoring Conolse &amp;gt; Indexing &amp;gt; Inputs &amp;gt; HTTP Event Collector: Instance , it's returns "You currently have no tokens configured" . I'm not sure how to fix this.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 04:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/528055#M89025</guid>
      <dc:creator>malikperang</dc:creator>
      <dc:date>2020-11-05T04:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Index has empty data when using HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/528128#M89034</link>
      <description>&lt;P&gt;It's possible the MC is not aware of HEC tokens on indexers.&amp;nbsp; Test that by running the following command on one of the indexers.&amp;nbsp; It should return your HEC token.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl -k -u admin:changeme https://localhost:8089/servicesNS/admin/splunk_httpinput/data/inputs/http&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 05 Nov 2020 14:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/528128#M89034</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-05T14:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Index has empty data when using HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/528142#M89036</link>
      <description>When you said forwarder are you meaning UF or HF? In which instance you are sending those HEC messages?</description>
      <pubDate>Thu, 05 Nov 2020 15:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-has-empty-data-when-using-HEC/m-p/528142#M89036</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-05T15:02:45Z</dc:date>
    </item>
  </channel>
</rss>

