I can see http_event_collector_metrics.log logs under
$SPLUNK_HOME/var/log/introspection/splunk/
But splunk says latest event received was 2 days ago. Whats going wrong in http event collector as I cannot see data if I select index after 7th of may. Previous data is available
Hi @Amandeepsin
The _introspection index data is splunk's internal metrics regarding HEC performance and connection.
You need to check the own index into which the data is coming in.
Here is the sample event.
Thanks
Hi,
Latest event to that own index which is mentioned in HEC source is 2 days ago. But in _introspection I can see events.
Any comments!!
Thanks,