<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HttpInputDataHandler - Parsing error : No data in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/583322#M8783</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you manage to resolve this issue and work out the root cause?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Feb 2022 05:57:02 GMT</pubDate>
    <dc:creator>danan5</dc:creator>
    <dc:date>2022-02-02T05:57:02Z</dc:date>
    <item>
      <title>HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476600#M3947</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;
&lt;P&gt;I got the following error a lot: "ERROR HttpInputDataHandler - Parsing error : No data"&lt;/P&gt;
&lt;P&gt;I guess it is related to HEC but I don't understand it nor find info about it.&lt;/P&gt;
&lt;P&gt;Would anyone know more about this error?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 00:04:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476600#M3947</guid>
      <dc:creator>D2SI</dc:creator>
      <dc:date>2020-06-06T00:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476601#M3948</link>
      <description>&lt;P&gt;hi @D2SI , Even i am getting these errors, but i started noticing when i upgraded splunk from 7.0.1 to 8.0.0 and copied the same splunk_httpinput app from the old instance to new instance. Is it same case with you. are you seeing this errors after the upgrade?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 13:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476601#M3948</guid>
      <dc:creator>srinikrishna</dc:creator>
      <dc:date>2020-01-21T13:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476602#M3949</link>
      <description>&lt;P&gt;Figure out which configured HEC-Stanza generate the errors via  "Monitoring Console --&amp;gt; Indexing --&amp;gt; Input --&amp;gt; HTTP Event Collector: Deployment" and check the configuration on source side.&lt;/P&gt;

&lt;P&gt;The incoming requests from the affected source are not valid and can't be handled in a correct way by Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 15:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476602#M3949</guid>
      <dc:creator>Paul1896</dc:creator>
      <dc:date>2020-01-21T15:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476603#M3950</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/195775"&gt;@Paul1896&lt;/a&gt; &lt;/P&gt;

&lt;P&gt;On my heavy forwarder i cant see this Monitoring console as the logs are not storing in local machine. however on the indexer i do not have monitoring console. Is there any other way to verify this?&lt;/P&gt;

&lt;P&gt;I actually got this below error and stopped ingesting logs since then. I dont see any more errors also related to this hec data input in the logs after 8.30. there are other inputs working fine. and fyi i copied this splunk_httpinput folder from my old splunk instance to new splunk instance to avoid recreating all the tokens i had earlier. does this makes any issues ?&lt;/P&gt;

&lt;P&gt;01-21-2020 07:36:24.170 +0000 ERROR HttpInputDataHandler - Failed processing http input, token name=OpenBankingAggregateProd, channel=48C994DD-C1F5-462F-BAED-FC00694CF173, source_IP=10.84.31.115, reply=9, events_processed=0, http_input_body_size=2980144&lt;BR /&gt;
component = HttpInputDataHandlereventtype = splunkd-loghost = ip-10-84-17-157http_input_body_size = 2980144log_level = ERRORmessage = Failed processing http input, token name=OpenBankingAggregateProd, channel=48C994DD-C1F5-462F-BAED-FC00694CF173, source_IP=10.84.31.115, reply=9, events_processed=0, http_input_body_size=2980144&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476603#M3950</guid>
      <dc:creator>srinikrishna</dc:creator>
      <dc:date>2020-09-30T03:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476604#M3951</link>
      <description>&lt;P&gt;Hi @srinikrishna, same here, upgraded from 7.0.x from 7.2.8, then started noticing the errors. I have activated DEBUG and I believe these errors match this kind of messages indicating that no data was processed:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01-21-2020 21:35:51.653 +0000 DEBUG HttpInputDataHandler - handled token: &amp;lt;token&amp;gt;, channel: &amp;lt;channel&amp;gt;, source IP: &amp;lt;ip&amp;gt;, reply: 9, processed: 0, http input body size: 679733
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But I can see these &lt;STRONG&gt;processed: 0&lt;/STRONG&gt; messages for plenty of tokens, most of them working fine and indexing data so I am confused how to interpret this.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 12:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476604#M3951</guid>
      <dc:creator>D2SI</dc:creator>
      <dc:date>2020-01-22T12:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476605#M3952</link>
      <description>&lt;P&gt;Thanks @Paul1896 ! I had not checked that way.&lt;/P&gt;

&lt;P&gt;There is no invalid request.&lt;/P&gt;

&lt;P&gt;But there are some 'parser errors'. The cool thing is that you can browse 'parser errors' by token. But like I said in the comment above, it matches plenty tokens not just one or two. Plus these tokens are OK, I mean there is data indexed through them, not no data at all.&lt;/P&gt;

&lt;P&gt;So I am wondering what are these 'parser errors' ? I mean, from the logs, it does not seem to be timestamp issues.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 13:45:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476605#M3952</guid>
      <dc:creator>D2SI</dc:creator>
      <dc:date>2020-01-22T13:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476606#M3953</link>
      <description>&lt;P&gt;Now In 7.3.4, we still have the "Parsing error : No data" error.&lt;/P&gt;

&lt;P&gt;We now have more detailed errors in splunkd logs :&lt;/P&gt;

&lt;P&gt;02-21-2020 10:35:22.634 +0000 ERROR HttpInputDataHandler - Failed processing http input, token name=, channel=, source_IP=1.2.3.4, reply=5, events_processed=0, http_input_body_size=0&lt;/P&gt;

&lt;P&gt;It still being generated for multiple HEC inputs, which are working (data being ingested, no invalid token or other significant errors).&lt;/P&gt;

&lt;P&gt;And we still do not understand why it is being generated &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/476606#M3953</guid>
      <dc:creator>D2SI</dc:creator>
      <dc:date>2020-09-30T04:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/583322#M8783</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you manage to resolve this issue and work out the root cause?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 05:57:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/583322#M8783</guid>
      <dc:creator>danan5</dc:creator>
      <dc:date>2022-02-02T05:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/593845#M8901</link>
      <description>&lt;P&gt;Bumping this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently leverage AWS Kinesis firehose to ingest log data via HEC. We recently started to see an increase number of "no data" errors reported via the Splunk HEC endpoint.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However log data appears to continue to function as expected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 19:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/593845#M8901</guid>
      <dc:creator>TellTaleMajora</dc:creator>
      <dc:date>2022-04-14T19:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/639776#M9546</link>
      <description>&lt;P&gt;I believe these can be safely ignored as "keep alive" calls from firehose/load balancers checking the connection but not sending data.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Putting in docs feedback on troubleshooting hec and firehose docs for future reference&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 14:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/639776#M9546</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2023-04-13T14:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/657097#M9794</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/160866"&gt;@mattymo&lt;/a&gt;this happened to us as well, but only when we moved to a load balancer in front of our indexers. Our previous step, which was HEC on a heavy forwarder, we never had this issue. Do you know if this is specific to load balanced HEC?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 22:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/657097#M9794</guid>
      <dc:creator>ejwade</dc:creator>
      <dc:date>2023-09-08T22:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: HttpInputDataHandler - Parsing error : No data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/673958#M9966</link>
      <description>&lt;P&gt;Yes, it would be specific to HEC clients that check for the endpoint's availability with tcp connections but not sending data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would not happen with HF because HTTP traffic would come in HF then be sent via S2S protocol to Indexers, which wouldnt do the checks like that.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;sorry for the answer from far in the future &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 15:58:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/HttpInputDataHandler-Parsing-error-No-data/m-p/673958#M9966</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2024-01-11T15:58:55Z</dc:date>
    </item>
  </channel>
</rss>

