Getting Data In

6.3 Upgrade - Missing HTTP Event Collector Data Input Option

Explorer

I just upgraded a local install of Splunk Enterprise from 6.2.4 (iirc) to 6.3. Restarted it, etc.

I'm not seeing the option to enable HTTP Event Collector in Settings -> Data Inputs. Although I was able to create a token in Data Inputs.

I could simply uninstall completely and reinstall, but I was hoping to not have to do that, as I have stuff in development. Is there an easy way to get this option to show up?

Ubuntu, 64-bit.

Thanks!

Communicator

DB connect 1.2.2 was just released and it resolves this issue with DBX 1.x. Good job guys! 🙂

Splunk Employee
Splunk Employee

bear in mind that every combination of DB Connect v1 and a new platform would reintroduce the problem, which is one of the reasons that DBX 1 was EOLed.

Path Finder

Yup.. Looks like DB Connect was the culprit for me (see below) Upgraded to newest version (unavailable at the time of issue) and works now..

Thanks

0 Karma

Splunk Employee
Splunk Employee

known issue in DB Connect v1, shouldn't be an issue with v2.

0 Karma

Path Finder

Yes, I had splunk_httpinput , but i think in my case it is more than just the http_collector, may move my issue to another answers topic.

0 Karma

Splunk Employee
Splunk Employee

Can you open a support issue? Support can work with you and help diagnose the issue. It looks like something is going on as a few people have reported this.

0 Karma

Path Finder

I am running on 64 bit linux.

I tried disabling a few apps installed and still didn't get any further. It will just hang when clicking Settings/Data Inputs (not all inputs expected listed)/Add Data.. Just get "loading" . Interestingly enough, when I click on Add data, I don't even get anything in web_services.log (just "loading" in the UI") & nothing out of the ordinary for splunkd_ui_access.log

0 Karma

Path Finder

It is included in with 6.3, so yeah I had it.. I tried to remove it, just in case that was causing some of the issues and it seems like it is tied pretty close to 6.3 now (getting errors about not being found). copied back and restarted still same issue for me.

File "/opt/splunk/lib/python2.7/site-packages/splunk/entity.py", line 222, in getEntitiesAtomFeed
serverResponse, serverContent = rest.simpleRequest(uri, getargs=kwargs, sessionKey=sessionKey, raiseAllErrors=True)
File "/opt/splunk/lib/python2.7/site-packages/splunk/rest/
init_.py", line 529, in simpleRequest
raise splunk.ResourceNotFound(uri, extendedMessages=extractMessages(body))
ResourceNotFound: [HTTP 404] https://127.0.0.1:8089/servicesNS/admin/launcher/data/inputs/http; [{'code': None, 'type': 'ERROR', 'text': 'Application does not exist: splunk_httpinput'}]

0 Karma

Splunk Employee
Splunk Employee

Can you check if you have a splunk_httpinput app in etc/apps?

0 Karma

Path Finder

I noticed this for quite a few data inputs that I have on a test box. I am missing HTTP event collector, and a bunch of others.

I have files/TCP/UDP/database/scripts and that is all. in 6.3

Also, when I click "add data" my instance just hangs (web page). Everything works fine on splunk 6.2.X

On 6.2.5 I had TCP/UDP/Scripts/Database/Automatic (from the app)/MQTT/REST/SNMP/Wiredata/Stream/URL/Web-pages under local inputs and forwarded inputs (windows/tcp/udp/etc). I am still trying to go through and see if one of the apps is incompatible and is breaking 6.3 by disabling apps (unless I get a better idea).

,I noticed this for quite a few data inputs that I have on a test box. I am missing HTTP event collector, and

.When I click "add data" my instance just hangs.. works fine on splunk 6.2.X

I have files/TCP/UDP/database/scripts and that is all.

On 6.2.5 I had TCP/UDP/Scripts/Database/Automatic (from the app)/MQTT/REST/SNMP/Wiredata/Stream/URL/Web-pages under local inputs and forwarded inputs (windows/tcp/udp/etc). I am still trying to go through and see if one of the apps is incompatible and is breaking 6.3 by disabling apps (unless I get a better idea).

0 Karma

Splunk Employee
Splunk Employee

Which platform are you running on?

0 Karma

Splunk Employee
Splunk Employee

Sorry you are having issues.

You should see a 'Settings' button in the Event Collector Management screen, which if you click you can enable.

Are you saying there is no settings button?

Splunk Employee
Splunk Employee

evidently, there are compatibility issues between DBX and 6.3.
try removing the DBX app from splunk_home, and restart splunkd.

it should resolve this issue and render the Data Inputs Ui properly.

0 Karma

Splunk Employee
Splunk Employee

There is an updated version of DB Connect, 2.0.5, that fixes the compatibility issues with Splunk Enterprise 6.3.

0 Karma

Communicator

Will there be update for DB connect 1.x resolving this issue?

0 Karma

Splunk Employee
Splunk Employee

reported as a bug in: (SPL-107261) Upgrade 6.3 - incomplete Data inputs selection

0 Karma

Explorer

There is no link to the event collector management screen from the Data Inputs configuration section.

As indicated in the post above, we think it may have something to do with a not-properly-updated inputs.conf. I'll try it and see.

0 Karma

Splunk Employee
Splunk Employee

Got it. We're looking into this, thanks!

0 Karma

SplunkTrust
SplunkTrust

IIRC, your inputs.conf file should now have an [HTTP] stanza. As a workaround, you can manually edit the file to enable the HTTP Event Collector. Of course, you'll have to restart Splunk afterwards.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

Explorer

Ah, yeah, I believe the inputs.conf file wasn't updated properly via the upgrade.

Once I get access to the machine, I'm going to try editing the inputs.conf file, or, better yet, copying the file from a fresh install.

I'll report back when I get around to it. I'm at conf right now, so I didn't get around to it last night.

0 Karma