Getting Data In

HTTP Event collector

rahul2gupta
Path Finder

Hi  @gcusello ,

I am curious to know why I am able to see  HTTP Event collector under the Data Inputs on my Indexer where there is no HTTP Event collector on Search Head.

Indexer

rahul2gupta_0-1640162779167.png

 

Search Head

rahul2gupta_1-1640162819996.png

Regards,

Rahul Gupta

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Apart from @gcusello already said (that you see available input types; notice that count for most of them is zero), your deployment seems strange.

You have webui enabled on indexers - that's not very usual. In case of a cluster you typically deploy config with apps cluster-wide.

And you have inputs defined on search-head. That's also not very typical. I'd set up a heavy forwarder for that and leave search heads to do searching.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rahul2gupta,

In the available Data Inputs you have all the possible ones even if not enabled, but what's the problem?

could you better describe your architecture?

You have some Indexers and one or more Search Heads.

Then you enabled HEC Collector on one of your servers, which one: IDX, SH or HF?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...