Splunk Dev

I can see data in logs but not in index for http event collector

Amandeepsin
New Member

I can see http_event_collector_metrics.log logs under

$SPLUNK_HOME/var/log/introspection/splunk/

But splunk says latest event received was 2 days ago. Whats going wrong in http event collector as I cannot see data if I select index after 7th of may. Previous data is available

Tags (1)
0 Karma
1 Solution

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

View solution in original post

0 Karma

PowerPacked
Builder

Hi @Amandeepsin

The _introspection index data is splunk's internal metrics regarding HEC performance and connection.

You need to check the own index into which the data is coming in.

Here is the sample event.

alt text

Thanks

0 Karma

Amandeepsin
New Member

Hi,

Latest event to that own index which is mentioned in HEC source is 2 days ago. But in _introspection I can see events.

Any comments!!

Thanks,

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...