Deployment Architecture

HEC Log Drop During Bundle Reload

arielpconsolaci
Path Finder

Hi Splunkers,

Good day. My HEC tokens are currently configured in the Indexer Cluster, and during Indexer Bundle Push specifically during bundle reload, the HEC logging drops to 0. Is this normal?

HEC logs are indexing during bundle validation, indexer rolling restart, but not during the bundle reload.

Bundle Validation -> Bundle Reload -> Indexer Rolling Restart

HEC logging is also not distributed properly across indexers.

Seeking advise.

Thank you and Kind Regards,

Ariel

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...