I have Installed Splunk App For Infrastructure and Splunk add-on for infrastructure.
I have configured the HEC 8088 and the Receiving Port 9997.
I have installed a Linux Client with the script.
I made troubleshooting.
In Splunk Enterprise im looking metrics arriving from that customers
check if in the eventtypes there are indexes: usually in these apps there isn't the flter for indexes.
you can check this opening in search one panel and adding the filter index=your_index
To solve this problem, you could choose between two solutions:
put the indexes in the default search path [ Settings -- Access Controls -- Roles -- -- Indexes];
create an eventtype with index=your_index and put this eventtype in each eventtype or macro of your App.
I prefer the second though it requests more work, because it's more clear and more performant.