Getting Data In

HTTP Event collector

rahul2gupta
Path Finder

Hi  @gcusello ,

I am curious to know why I am able to see  HTTP Event collector under the Data Inputs on my Indexer where there is no HTTP Event collector on Search Head.

Indexer

rahul2gupta_0-1640162779167.png

 

Search Head

rahul2gupta_1-1640162819996.png

Regards,

Rahul Gupta

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Apart from @gcusello already said (that you see available input types; notice that count for most of them is zero), your deployment seems strange.

You have webui enabled on indexers - that's not very usual. In case of a cluster you typically deploy config with apps cluster-wide.

And you have inputs defined on search-head. That's also not very typical. I'd set up a heavy forwarder for that and leave search heads to do searching.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rahul2gupta,

In the available Data Inputs you have all the possible ones even if not enabled, but what's the problem?

could you better describe your architecture?

You have some Indexers and one or more Search Heads.

Then you enabled HEC Collector on one of your servers, which one: IDX, SH or HF?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...