Getting Data In

Adding HEC input does not have option for app selection

termcap
Path Finder

Hi,

While adding an HEC input on the Splunk heavy forwarder, Splunk does not provide the option to select the app. I am using Splunk version 8.1.3 and build 63079c59e632

Is this a bug in the web interface in version 8.1.3 or has the option been removed do to some reason.

HEC input addition screenshot:

hec_input.PNG

Thanks,

Termcap

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I didn't find anything in the Release Notes about this so I presume it's a bug.  Open a support request.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

venkatasri
SplunkTrust
SplunkTrust

Hi @termcap 

I have tested it, 'App context' available to choose on my 8.1.3 single instance Splunk and HF both.

could be a bug in your version and find for errors in installation, try configure it from backend inside one of app.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I didn't find anything in the Release Notes about this so I presume it's a bug.  Open a support request.

---
If this reply helps you, Karma would be appreciated.

termcap
Path Finder

Hi @richgalloway 

I do not have payed support with Splunk, So I just hope someone from Splunk is able to take it further from this thread. (Or is it possible to raise a bug request or something similar ? )

Thanks,

Termcap.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...