Hi,
I have setup a HEC input on a Heavy Forwarder and have a base app for all data outputs to forward to Splunk Cloud Indexers but not seeing the HEC data in Cloud.
Am I missing out a particular setting that forwards HEC data
Thanks,
Make sure you're using the "Universal Forwarder" app downloaded from your Splunk Cloud search head.
Check the HF's splunkd.log for messages explaining why it cannot connect to Splunk Cloud.
Have you check the last chance index for the HEC data?