All Apps and Add-ons

How is performance of HTTP Event Collector ?

c71996
Explorer

How HTTP event Collector is reliable ?

If i use it for collecting application logs . Does it garranty collection of 100% data . It can't miss data alos due tk some error...if this is the case how to to handle?

0 Karma

nickhills
Ultra Champion

It can be made 'reliable' if your client code supports it.

However, if ease of deployment is important to you (or you dont want to implement logic into your HEC client), a universal forwarder with indexer acknowledgement provides a robust level of durability.

See:

Forwarders - https://docs.splunk.com/Documentation/Splunk/8.0.1/Forwarding/Protectagainstlossofin-flightdata
HEC Indexer Ack - https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/AboutHECIDXAck

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

You should be aware that there is a tradeoff with IndexerAck, and that is that you can end up with duplicate events where indexerAck has triggered a re-attempt.

If my comment helps, please give it a thumbs up!
0 Karma

c71996
Explorer

So with this i came to conclusion that HEC + ack gives reliable service.

Here is first i send a event data and receive ack num . I query ack tk check the indexing status . If status is positive event is indexed .

If status is negative ...what would be my action item ? I need to wait or resend event ?

0 Karma

nickhills
Ultra Champion

Yes, exactly that.
If you are comfortable building a client to send your logs from your own application etc, then HEC is definitely the way to go.

If you are looking to collect log files created by other applications or 3rd parties, then use a forwarder.

If my comment helps, please give it a thumbs up!
0 Karma

c71996
Explorer

Is forwarder more reliable than HEC ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...