Building for the Splunk Platform

I can see data in logs but not in index for http event collector

Amandeepsin
New Member

I can see http_event_collector_metrics.log logs under

$SPLUNK_HOME/var/log/introspection/splunk/

But splunk says latest event received was 2 days ago. Whats going wrong in http event collector as I cannot see data if I select index after 7th of may. Previous data is available

Tags (1)
0 Karma
1 Solution

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

View solution in original post

0 Karma

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

0 Karma

Amandeepsin
New Member

Hi,

Latest event to that own index which is mentioned in HEC source is 2 days ago. But in _introspection I can see events.

Any comments!!

Thanks,

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...