Getting Data In

Fields not recognized in Events from HTTP Event Collector (HEC)

jfrankman
Loves-to-Learn Lots

We are noticing that that same data received via the HTTP Event Collector is not searchable by Field like data received via our Forwarders.

Note how EventName field IS NOT being picked up from Event received through HEC:

jfrankman_1-1693424382299.png

 

Note how EventName IS getting picked up from Event received through Forwarders:

jfrankman_0-1693424317126.png

 

It seems that the events received through the HEC are treated as one large Blob of data and are not parsed or indexed the same way by Splunk. I there anything that can be done in the request to the HEC or to an indexer to resolve this?

Thanks.

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...