I just upgraded a local install of Splunk Enterprise from 6.2.4 (iirc) to 6.3. Restarted it, etc.
I'm not seeing the option to enable HTTP Event Collector in Settings -> Data Inputs. Although I was able to create a token in Data Inputs.
I could simply uninstall completely and reinstall, but I was hoping to not have to do that, as I have stuff in development. Is there an easy way to get this option to show up?
Ubuntu, 64-bit.
Thanks!
DB connect 1.2.2 was just released and it resolves this issue with DBX 1.x. Good job guys! 🙂
bear in mind that every combination of DB Connect v1 and a new platform would reintroduce the problem, which is one of the reasons that DBX 1 was EOLed.
Yup.. Looks like DB Connect was the culprit for me (see below) Upgraded to newest version (unavailable at the time of issue) and works now..
Thanks
known issue in DB Connect v1, shouldn't be an issue with v2.
Yes, I had splunk_httpinput , but i think in my case it is more than just the http_collector, may move my issue to another answers topic.
Can you open a support issue? Support can work with you and help diagnose the issue. It looks like something is going on as a few people have reported this.
I am running on 64 bit linux.
I tried disabling a few apps installed and still didn't get any further. It will just hang when clicking Settings/Data Inputs (not all inputs expected listed)/Add Data.. Just get "loading" . Interestingly enough, when I click on Add data, I don't even get anything in web_services.log (just "loading" in the UI") & nothing out of the ordinary for splunkd_ui_access.log
It is included in with 6.3, so yeah I had it.. I tried to remove it, just in case that was causing some of the issues and it seems like it is tied pretty close to 6.3 now (getting errors about not being found). copied back and restarted still same issue for me.
File "/opt/splunk/lib/python2.7/site-packages/splunk/entity.py", line 222, in getEntitiesAtomFeed
serverResponse, serverContent = rest.simpleRequest(uri, getargs=kwargs, sessionKey=sessionKey, raiseAllErrors=True)
File "/opt/splunk/lib/python2.7/site-packages/splunk/rest/init_.py", line 529, in simpleRequest
raise splunk.ResourceNotFound(uri, extendedMessages=extractMessages(body))
ResourceNotFound: [HTTP 404] https://127.0.0.1:8089/servicesNS/admin/launcher/data/inputs/http; [{'code': None, 'type': 'ERROR', 'text': 'Application does not exist: splunk_httpinput'}]
Can you check if you have a splunk_httpinput app in etc/apps?
I noticed this for quite a few data inputs that I have on a test box. I am missing HTTP event collector, and a bunch of others.
I have files/TCP/UDP/database/scripts and that is all. in 6.3
Also, when I click "add data" my instance just hangs (web page). Everything works fine on splunk 6.2.X
On 6.2.5 I had TCP/UDP/Scripts/Database/Automatic (from the app)/MQTT/REST/SNMP/Wiredata/Stream/URL/Web-pages under local inputs and forwarded inputs (windows/tcp/udp/etc). I am still trying to go through and see if one of the apps is incompatible and is breaking 6.3 by disabling apps (unless I get a better idea).
,I noticed this for quite a few data inputs that I have on a test box. I am missing HTTP event collector, and
.When I click "add data" my instance just hangs.. works fine on splunk 6.2.X
I have files/TCP/UDP/database/scripts and that is all.
On 6.2.5 I had TCP/UDP/Scripts/Database/Automatic (from the app)/MQTT/REST/SNMP/Wiredata/Stream/URL/Web-pages under local inputs and forwarded inputs (windows/tcp/udp/etc). I am still trying to go through and see if one of the apps is incompatible and is breaking 6.3 by disabling apps (unless I get a better idea).
Which platform are you running on?
Sorry you are having issues.
You should see a 'Settings' button in the Event Collector Management screen, which if you click you can enable.
Are you saying there is no settings button?
evidently, there are compatibility issues between DBX and 6.3.
try removing the DBX app from splunk_home, and restart splunkd.
it should resolve this issue and render the Data Inputs Ui properly.
There is an updated version of DB Connect, 2.0.5, that fixes the compatibility issues with Splunk Enterprise 6.3.
Will there be update for DB connect 1.x resolving this issue?
reported as a bug in: (SPL-107261) Upgrade 6.3 - incomplete Data inputs selection
There is no link to the event collector management screen from the Data Inputs configuration section.
As indicated in the post above, we think it may have something to do with a not-properly-updated inputs.conf. I'll try it and see.
Got it. We're looking into this, thanks!
IIRC, your inputs.conf file should now have an [HTTP] stanza. As a workaround, you can manually edit the file to enable the HTTP Event Collector. Of course, you'll have to restart Splunk afterwards.
Ah, yeah, I believe the inputs.conf file wasn't updated properly via the upgrade.
Once I get access to the machine, I'm going to try editing the inputs.conf file, or, better yet, copying the file from a fresh install.
I'll report back when I get around to it. I'm at conf right now, so I didn't get around to it last night.