Getting Data In

Adding HEC input does not have option for app selection

termcap
Path Finder

Hi,

While adding an HEC input on the Splunk heavy forwarder, Splunk does not provide the option to select the app. I am using Splunk version 8.1.3 and build 63079c59e632

Is this a bug in the web interface in version 8.1.3 or has the option been removed do to some reason.

HEC input addition screenshot:

hec_input.PNG

Thanks,

Termcap

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I didn't find anything in the Release Notes about this so I presume it's a bug.  Open a support request.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

venkatasri
SplunkTrust
SplunkTrust

Hi @termcap 

I have tested it, 'App context' available to choose on my 8.1.3 single instance Splunk and HF both.

could be a bug in your version and find for errors in installation, try configure it from backend inside one of app.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I didn't find anything in the Release Notes about this so I presume it's a bug.  Open a support request.

---
If this reply helps you, Karma would be appreciated.

termcap
Path Finder

Hi @richgalloway 

I do not have payed support with Splunk, So I just hope someone from Splunk is able to take it further from this thread. (Or is it possible to raise a bug request or something similar ? )

Thanks,

Termcap.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...