All Apps and Add-ons

HEC Troubleshooting -Why are we Not getting events?

SplunkDash
Motivator

Hello,

SPLUNK used to get data through HEC using 8088 port.  But when we moved it to a new HF with new token it's now stopped getting data under new setting. Nothing has changed except the HF/server/token used. Any recommendation will be highly appreciated. Thank you so much. 

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Have you check that you have gotten anything else from that HF?

If it send internal logs to your indexers then you should check that you have enabled HEC on that HF with the same parameters than in old HF. Check also that it has valid certs if you are previously used HEC over https (you should). After that you should check individual HEC tokens that those are correctly set.

If/when you have MC up and running you could add both HF as an indexer to it and use then it's dashboards to check what happening there (Settings -> MC -> Indexing -> Inputs -> HEC ...)

Another way is to use "splunk btool inputs list --debug" on cmd line on those HFs and check what differences those have.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Have you check that you have gotten anything else from that HF?

If it send internal logs to your indexers then you should check that you have enabled HEC on that HF with the same parameters than in old HF. Check also that it has valid certs if you are previously used HEC over https (you should). After that you should check individual HEC tokens that those are correctly set.

If/when you have MC up and running you could add both HF as an indexer to it and use then it's dashboards to check what happening there (Settings -> MC -> Indexing -> Inputs -> HEC ...)

Another way is to use "splunk btool inputs list --debug" on cmd line on those HFs and check what differences those have.

r. Ismo

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...