<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Metric value= is not valid Metric event data with an invalid metric value would not be indexed. Ensure the input metric data is not malformed. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Metric-value-is-not-valid-Metric-event-data-with-an-invalid/m-p/432804#M95459</link>
    <description>&lt;P&gt;I've seen that before. Is the sourcetype defined appropriately to process that into metrics data? I can't recall if the requirements on the HEC sourcetype side are explained in the docs.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Apr 2019 17:13:10 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2019-04-01T17:13:10Z</dc:date>
    <item>
      <title>Metric value= is not valid Metric event data with an invalid metric value would not be indexed. Ensure the input metric data is not malformed.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metric-value-is-not-valid-Metric-event-data-with-an-invalid/m-p/432803#M95458</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've integrated collectd metrics with Splunk 6.x via HEC in the past but  getting some issues recently with collectd 5.8.1 on Splunk 7.2.4.2.&lt;/P&gt;

&lt;P&gt;need clues ... getting errors while trying ingest collectd metrics... haven't see this before. I get the errors in the SH "Messages" in the black nav bar ... but can't see the error messages themselves in the _internal index.&lt;BR /&gt;
Error msgs&lt;BR /&gt;
search peer idx-xyzmydomain.com has the following message: Metric value= is not valid for source=collectd_hec_token, sourcetype=httpevent, host=aa.xx.yy.zz, index=linux_metrics. Metric event data with an invalid metric value would not be indexed. Ensure the input metric data is not malformed. Example of collectd payload is given below ... appreciate any hint as to what is wrong with the format of the data. Followed verbatim &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.4/Metrics/GetMetricsInCollectd" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.4/Metrics/GetMetricsInCollectd&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[{"values":[0],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"thermal","plugin_instance":"cooling_device1","type":"gauge","type_instance":""},{"values":[null],"dstypes":["derive"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"irq","plugin_instance":"","type":"irq","type_instance":"HYP"},{"values":[null],"dstypes":["derive"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"irq","plugin_instance":"","type":"irq","type_instance":"PIN"},{"values":[null],"dstypes":["derive"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"irq","plugin_instance":"","type":"irq","type_instance":"NPI"},{"values":[null],"dstypes":["derive"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"irq","plugin_instance":"","type":"irq","type_instance":"PIW"},{"values":[0],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"","type":"ps_state","type_instance":"running"},{"values":[101],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"","type":"ps_state","type_instance":"sleeping"},{"values":[0],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"","type":"ps_state","type_instance":"zombies"},{"values":[null],"dstypes":["derive"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"irq","plugin_instance":"","type":"irq","type_instance":"MCP"},{"values":[0],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"","type":"ps_state","type_instance":"stopped"},{"values":[null],"dstypes":["derive"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"irq","plugin_instance":"","type":"irq","type_instance":"MIS"},{"values":[null],"dstypes":["derive"],"dsnames":["value"],"time":1552624141.826,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"irq","plugin_instance":"","type":"irq","type_instance":"ERR"},{"values":[0],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"","type":"ps_state","type_instance":"paging"},{"values":[4949405696],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"all","type":"ps_data","type_instance":""},{"values":[9698123776],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"all","type":"ps_vm","type_instance":""},{"values":[0],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"","type":"ps_state","type_instance":"blocked"},{"values":[null,null],"dstypes":["derive","derive"],"dsnames":["user","syst"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"all","type":"ps_cputime","type_instance":""},{"values":[503173120],"dstypes":["gauge"],"dsnames":["value"],"time":1552624141.837,"interval":60.000,"host":"myhost.us-east-1a.aws.mydomain.com","plugin":"processes","plugin_instance":"all","type":"ps_rss","type_instance":""}]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metric-value-is-not-valid-Metric-event-data-with-an-invalid/m-p/432803#M95458</guid>
      <dc:creator>smitra_splunk</dc:creator>
      <dc:date>2020-09-29T23:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Metric value= is not valid Metric event data with an invalid metric value would not be indexed. Ensure the input metric data is not malformed.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metric-value-is-not-valid-Metric-event-data-with-an-invalid/m-p/432804#M95459</link>
      <description>&lt;P&gt;I've seen that before. Is the sourcetype defined appropriately to process that into metrics data? I can't recall if the requirements on the HEC sourcetype side are explained in the docs.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 17:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metric-value-is-not-valid-Metric-event-data-with-an-invalid/m-p/432804#M95459</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-04-01T17:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Metric value= is not valid Metric event data with an invalid metric value would not be indexed. Ensure the input metric data is not malformed.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metric-value-is-not-valid-Metric-event-data-with-an-invalid/m-p/432805#M95460</link>
      <description>&lt;P&gt;You are right. The docs don't mention the sourcetype either on the inputs.conf or in the collectd.conf.  The sourcetype=collectd_http need to mentioned either file - in the former under the HEC input stanza and in the latter as part of the URL in the write_http plugin section. The basic examples only hint at the sourcetype in the curl examples in the document "a beginner's guide to collectd".&lt;BR /&gt;
anyway ... learnt my lesson... I had better success using the Splunk App for Infrastructure which has detailed step by step documentation and integrated install scriptlets of all components.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:00:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metric-value-is-not-valid-Metric-event-data-with-an-invalid/m-p/432805#M95460</guid>
      <dc:creator>smitra_splunk</dc:creator>
      <dc:date>2020-09-30T00:00:31Z</dc:date>
    </item>
  </channel>
</rss>

