Getting Data In

HTTP Event collector

rahul2gupta
Path Finder

Hi  @gcusello ,

I am curious to know why I am able to see  HTTP Event collector under the Data Inputs on my Indexer where there is no HTTP Event collector on Search Head.

Indexer

rahul2gupta_0-1640162779167.png

 

Search Head

rahul2gupta_1-1640162819996.png

Regards,

Rahul Gupta

 

Labels (1)
0 Karma

PickleRick
Ultra Champion

Apart from @gcusello already said (that you see available input types; notice that count for most of them is zero), your deployment seems strange.

You have webui enabled on indexers - that's not very usual. In case of a cluster you typically deploy config with apps cluster-wide.

And you have inputs defined on search-head. That's also not very typical. I'd set up a heavy forwarder for that and leave search heads to do searching.

0 Karma

gcusello
Esteemed Legend

Hi @rahul2gupta,

In the available Data Inputs you have all the possible ones even if not enabled, but what's the problem?

could you better describe your architecture?

You have some Indexers and one or more Search Heads.

Then you enabled HEC Collector on one of your servers, which one: IDX, SH or HF?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...