Getting Data In

HTTP Event collector

rahul2gupta
Path Finder

Hi  @gcusello ,

I am curious to know why I am able to see  HTTP Event collector under the Data Inputs on my Indexer where there is no HTTP Event collector on Search Head.

Indexer

rahul2gupta_0-1640162779167.png

 

Search Head

rahul2gupta_1-1640162819996.png

Regards,

Rahul Gupta

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Apart from @gcusello already said (that you see available input types; notice that count for most of them is zero), your deployment seems strange.

You have webui enabled on indexers - that's not very usual. In case of a cluster you typically deploy config with apps cluster-wide.

And you have inputs defined on search-head. That's also not very typical. I'd set up a heavy forwarder for that and leave search heads to do searching.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rahul2gupta,

In the available Data Inputs you have all the possible ones even if not enabled, but what's the problem?

could you better describe your architecture?

You have some Indexers and one or more Search Heads.

Then you enabled HEC Collector on one of your servers, which one: IDX, SH or HF?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...